Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 2.2 Moderate: Symlink Attack in Joe Editor Advisory

debian
Calendar Grey November 22, 2000
Debian Logo
- ------------------------------------------------------------------------ Debian Security Advisory
When joe dies to a signal instead of a normal exit it is vulnerable to a symlink attack.

Summary

Package : joe
Problem type : symlink attack
Debian-specific: no

When joe (Joe's Own Editor) dies due to a signal instead of a normal
exit it saves a list of the files it is editing to a file called `DEADJOE'
in its current directory. Unfortunately this wasn't done safely which made
joe vulnerable to a symlink attack.

This has been fixed in version 2.8-15.1 .

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.


Debian GNU/Linux 2.2 alias potato

Potato was released for alpha, arm, i386, m68k, powerpc and sparc.

Source archives:


MD5 checksum: 94131d7638b028e6bd6f529747b9d318


MD5 checksum: 5ad45a1fa1a293bef03786f9258bf846


MD5 checksum: 84c1aebfce7876b8639945da3c29f204

Alpha architecture:


MD5 checksum: defbc5c39a2ae8ed000b7b302ecd339f

ARM architecture:


MD5 checksum: bcb70726840c2cf11cba068ce2a826be

Intel ia32 architecture:


MD5 checksum: 21444255b240be01132208e5cb1d3439

Motoro...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here