what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

debian.nvi.txt

debian.nvi.txt
Posted Jan 10, 2000

The version of nvi that was distributed with Debian GNU/Linux 2.1 has an error in the default /etc/init.d/nviboot script: it did not handle filenames with embedded spaces correctly. This made it possible to remove files in the root directory by creating entries in /var/tmp/vi.recover. Debian security homepage here.

tags | root
systems | linux, debian
SHA-256 | 6d4d0a9f29c0d75e85c71619ed6c28d2c170f546ad98962ee9eee00a03583594

debian.nvi.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----

- ------------------------------------------------------------------------
Debian Security Advisory security@debian.org
http://www.debian.org/security/ Wichert Akkerman
January 9, 2000
- ------------------------------------------------------------------------


Package: nvi
Vulnerability type: local attack
Debian-specific: no

The version of nvi that was distributed with Debian GNU/Linux 2.1 has
an error in the default /etc/init.d/nviboot script: it did not handle
filenames with embedded spaces correctly. This made it possible to remove
files in the root directory by creating entries in /var/tmp/vi.recover.

This has been fixed in version 1.79-9.1 . We recommend you upgrade your nvi
package immediately.

If you use a customized version of nviboot please make sure your version
does not suffer from this problem. If you upgrade dpkg will offer to replace
it with the new safe version if needed.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink
- --------------------------------

This version of Debian was released only for Intel ia32, the Motorola
680x0, the alpha and the Sun sparc architecture.

Source archives:
http://security.debian.org/dists/stable/updates/source/nvi_1.79-9.1.diff.gz
MD5 checksum: 95d8dbe42dc0c68f4fdcd99437b8c9b4
http://security.debian.org/dists/stable/updates/source/nvi_1.79-9.1.dsc
MD5 checksum: 40db70d26e6b68a234e4b9c394603b7e
http://security.debian.org/dists/stable/updates/source/nvi_1.79.orig.tar.gz
MD5 checksum: 0270bbfed66bacb94ddaf0e6f39bd9d1

Alpha architecture:
http://security.debian.org/dists/stable/updates/binary-alpha/nvi_1.79-9.1_alpha.deb
MD5 checksum: 16445e2a10aa48a0fda36868270ef5c2

Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/binary-i386/nvi_1.79-9.1_i386.deb
MD5 checksum: aa056275853c9884c24dc6a421cde8a0

Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/binary-m68k/nvi_1.79-9.1_m68k.deb
MD5 checksum: 8eb154cfe1c4c75dea55148ce6ca735f

Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/binary-sparc/nvi_1.79-9.1_sparc.deb
MD5 checksum: 0b5019e39b9be3e00762e1526badcaaa


These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/ soon.


For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .

- --
- ----------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable updates
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates
Mailing list: debian-security-announce@lists.debian.org

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQB1AwUBOHfvdKjZR/ntlUftAQEgOQL+LsYBMBHg7fQ8CMkK2PRQdSjuxI5+epav
6TNCg/eavbuhAcLXuAW4sfFBZ6fYTfNNeBCdIrlKuNF9J5/oOybvjSOc/6aALD5b
RmlV3MiIh5ikie8b4r4mSbG2mvo2Q8MB
=Tlju
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close