security advisorysecurity issueDebian
Exploit exists that could result in a malicious user obtaining group mailman permission.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------------- Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 5, 2000 - ---------------------------------------------------------------------------- Package: mailman Vulnerability: local mailman group exploit Debian-specific: no Former versions of mailman v2.0 came with a security problem, introduced during the 2.0 beta cycle, that could be exploited by clever local users to gain group mailman permission. No exploit does exist at the moment, though. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink - -------------------------------- Slink comes with version 1.0 that is not vulnerable. Debian 2.2 alias potato - ----------------------- Potato comes with version 1.1 that is not vulnerable. Debian Unstable alias woody - --------------------------- This version of Debian is not yet released and reflects the current development release. Fixes are currently available for Intel ia32 and Motorola 680x0. Fixes for other architectures will be available soon. In doubt, please recompile the package from source on your own. Source archives: MD5 checksum: 177e666144c35d6b945b30dddf567fef MD5 checksum: 431d66e4ef496ce48463ed55193d375c MD5 checksum: 2c2602b7745a56adecd4f24fdd6d446f Intel ia32 architecture: MD5 checksum: e2a071bf4a9a3be02978df47ed58acb6 Motorola 680x0 architecture: MD5 checksum: 8bb6367c1e249beaaaa8eb3b7fc71c27 - ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable updates For dpkg-ftp: dists/stable/updates Mailing list:debian-security- This email address is being protected from spambots. You need JavaScript enabled to view it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: For info see The GNU Privacy Guard iD8DBQE5jVi0W5ql+IAeqTIRAntHAJ4qPqO9uLQirRFsl48T5Uv729A6/QCfUAiJ k+20YJsL9L3+SBCkm2KOxic=7iAZ -----END PGP SIGNATURE----- . This alert highlights vulnerabilities in Sendmail on Ubuntu, focusing on internal exploits and access issues. Admins should implement enhanced security measures. mailman Exploit, Debian Security, Local Access Mitigation. . Severity: Important. LinuxSecurity.com Team
Aug 06, 2000
•Important
Debian