[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

/tmp symlink problems in man



Hi!

	Is debian affected too? For the message it seems it is as slink
uses 2.3.10.

	Any confirmation would be appreciated.

-- p.

---------- Forwarded message ----------
Date: Sat, 5 Jun 1999 22:02:19 +0200
From: Marc Heuse <marc@SUSE.DE>
To: BUGTRAQ@NETSPACE.ORG
Subject: Re: /tmp symlink problems in SuSE Linux 6.1

Hi,

we confirmed the link vulnerablity in the man package.
The culprit is zsoelim which creates the file without looking left and
right. :-(

All linux distributions using man 2.3.10 should be affected.

A fixed package from us will be available soon.

Greets,
	Marc
--
   Marc Heuse, SuSE GmbH, Schanzaeckerstr. 10, 90443 Nuernberg
   E@mail: marc@suse.de  Function: Security Support & Auditing
   "lynx -source http://www.suse.de/~marc/marc.pgp | pgp -fka"
Key fingerprint = B5 07 B6 4E 9C EF 27 EE  16 D9 70 D4 87 B5 63 6C


Reply to: