Package        : tmpreaper
Version        : 1.6.13+nmu1+deb8u1
CVE ID         : CVE-2019-3461
Debian Bug     : 918956

It was discovered that tmpreaper, a program that cleans up files in
directories based on their age, is vulnerable to a race condition. This
vulnerability might be exploited by local attackers to perform privilege
escalation.

For Debian 8 "Jessie", this problem has been fixed in version
1.6.13+nmu1+deb8u1.

We recommend that you upgrade your tmpreaper packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1640-1: tmpreaper security update

January 24, 2019
It was discovered that tmpreaper, a program that cleans up files in directories based on their age, is vulnerable to a race condition

Summary

We recommend that you upgrade your tmpreaper packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : tmpreaper
Version : 1.6.13+nmu1+deb8u1
CVE ID : CVE-2019-3461
Debian Bug : 918956

Related News