New version of mirror fixes remote exploit

    Date13 Dec 1999
    CategoryDebian
    2199
    Posted ByLinuxSecurity Advisories
    We have received reports that the version of mirror as distributed in Debian GNU/Linux 2.1 could be remotely exploited. When mirroring a remote site the remote site could use filename-constructions like " .." that would case mirror to work one level above the target directory for the mirrored files.
    -----BEGIN PGP SIGNED MESSAGE-----
    
    - ------------------------------------------------------------------------
    Debian Security Advisory                             This email address is being protected from spambots. You need JavaScript enabled to view it.
    http://www.debian.org/security/      
                       Wichert Akkerman
    October 18, 1999
    - ------------------------------------------------------------------------
    
    
    We have received reports that the version of mirror as distributed in
    Debian GNU/Linux 2.1 could be remotely exploited. When mirroring a
    remote site the remote site could use filename-constructions like " .."
    that would case mirror to work one level above the target directory for
    the mirrored files.
    
    This has been fixed in mirror version 2.9-2.1 .
    
    We recommend you upgrade your mirror package immediately.
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    Debian GNU/Linux 2.1 alias slink
    - --------------------------------
    
      This version of Debian was released only for Intel, the Motorola
      680x0, the alpha and the Sun sparc architecture.
    
      Source archives:
        http://security.debian.org/dists/stable/updates/source/mirror_2.9-
    2.1.diff.gz
          MD5 checksum: 2340c6a18b8b69c5122ef78e50663824
        http://security.debian.org/dists/stable/updates/source/mirror_2.9-
    2.1.dsc
          MD5 checksum: 2890c6ed6c60e97299c7fcd3a56b5b36
        http://security.debian.org/dists/stable/updates/source/mirror_2.9.orig.tar.
    gz
          MD5 checksum: 49ebf2fc732322aff2a8297f89bb9df3
    
      Architecture indendent archives:
        http://security.debian.org/dists/stable/updates/binary-
    all/mirror_2.9-2.1_all.deb
          MD5 checksum: d10e76994611915ba79aeee838fada7c
    
    - -- 
    - ----------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable 
    updates
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    Charset: noconv
    
    iQB1AwUBOApvGKjZR/ntlUftAQHFUAL+JRZXhVg1azFtZ6NgQQcVKok334nO7IIV
    Eqc6oQAAr3AcwUKF5gDOWEz5CExaVEncZPX4EJ5q1HVRwisCVupNG6lBcBJpN3s2
    PTqVU1A6Z0LRRZONRg5E2ou1B0ttaUO4
    =eBo8
    -----END PGP SIGNATURE-----
    
    

    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"5","type":"x","order":"1","pct":55.56,"resources":[]},{"id":"88","title":"Should be more technical","votes":"3","type":"x","order":"2","pct":33.33,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"1","type":"x","order":"3","pct":11.11,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.