All former versions of trn used a hardcoded filename in /tmp as temporary storage. If the file already exists as symbolic link to users files they will be overwritten. . All former versions of trn used a hardcoded filename in /tmp as temporary storage. If the file already exists as symbolic link to users files they will be overwritten. We recommend you upgrade your man2html package as soon as possible. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink -------------------------------- Source archives: MD5 checksum: a1b2a19ea060c289e079444edf908a18 MD5 checksum: 562b8ad926784d101646dc7148919015 Alpha architecture: MD5 checksum: 919bbf1ae668786ec945d4fb042d0d27 Intel ia32 architecture: MD5 checksum: b14c9ba3eeef6a33e574c55e022c47a4 Motorola 680x0 architecture: MD5 checksum: 3ad7ab653b333cfc4fb4409c7fe1e192 Sun Sparc architecture: MD5 checksum: 97cebe97d78372706c225309898a2e7d Debian GNU/Linux unstable alias potato -------------------------------------- Source archives: -9.4.diff.gz MD5 checksum: 46a3f905fecec6e9079ccb6e6c0d27dd MD5 checksum: e23192e418c3299f0bee0c5ef0f182e8 . tar.gz MD5 checksum: b42f4226072442265fbbda865ca4b796 Alpha architecture: MD5 checksum: bdcad9ead736edd1082bd203a26a3233 ARM architecture: MD5 checksum: f8c918679d759b3ec22a017eb58fc3b4 Intel ia32 architecture: MD5 checksum: d2a73698ac259196876a71fd6f45b714 Motorola 680x0 architecture: MD5 checksum: 0eb1b01ce9d3a92c2072ba8a6e7c81fa PowerPC architecture: MD5 checksum: 60ddaabdecb48ae2062d5d88ee608c42 Sun Sparc architecture: MD5 checksum: a1525fc83d73502be41411e02ba8ec3f --Debian GNU/Linux . Security Managers .
The news reader trn uses a hardcoded temporary file, which resides in /tmp. . ______________________________________________________________________________ SuSE Security Announcement Package: trn-3.x and previous versions Date: Tue Aug 25 09:28:15 CEST 1999 Affected: maybe all Unix operatingsystems using trn ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that that we provide this information on as "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. _____________________________________________________________________________ 1. Problem Description The news reader trn uses a hardcoded temporary file, which resides in /tmp. 2. Impact By creating a symbolic link in /tmp, files could be overwritten, if the privileges of the user executing trn permits that operation. 3. Solution Updated the trn package from our FTP server. ______________________________________________________________________________ Here are the md5 checksums of the upgrade packages, please verify these before installing the new packages: 55cd717cfabb6ca95c5e8255c58eb514 trn-3.6-70.i386.rpm 0738e9a26aca763c2a704e76f9adedf6 trn_spl-3.6-61.i386.rpm ______________________________________________________________________________ You will find the update on our ftp-Server: Webpage for patches: https://www.suse.com/de-de/ or try the following web pages for a list of mirrors: https://www.suse.com/de-de/ ______________________________________________________________________________ . Revise the trn package to mitigate security vulnerabilities connected to static temporary files on SuSE Linux systems.. trn Security Advisory, Temporary File Fix, Unix File Overwrite Issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.