Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Sign up!
EnGarde Community
What is the most important Linux security technology?
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Latest Newsletters
Linux Security Week: March 30th, 2015
Linux Advisory Watch: March 27th, 2015
LinuxSecurity Newsletters
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

Debian: New zhcon packages fix unauthorised file access Print E-mail
User Rating:      How can I rate this item?
Posted by Joseph Shakespeare   
Debian Erik Sjölund discovered that zhcon, a fast console CJK system using the Linux framebuffer, accesses a user-controlled configuration file with elevated privileges. Thus, it is possible to read arbitrary files.
- --------------------------------------------------------------------------
Debian Security Advisory DSA 655-1                                        Martin Schulze
January 25th, 2005               
- --------------------------------------------------------------------------

Package        : zhcon
Vulnerability  : missing privilege release
Problem-Type   : local
Debian-specific: no
CVE ID         : CAN-2005-0072

Erik Sjölund discovered that zhcon, a fast console CJK system using
the Linux framebuffer, accesses a user-controlled configuration file
with elevated privileges.  Thus, it is possible to read arbitrary

For the stable distribution (woody) this problem has been fixed in
version 0.2-4woody3.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your zhcon package.

Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:
      Size/MD5 checksum:      571 cef550eb0e12c8841fb19dec63b57c18
      Size/MD5 checksum:    18162 5757142ee30a5d3e990180a44bfbf8cd
      Size/MD5 checksum:  4727022 7a15d08e903c0d40f1f659b23185c4c0

  Alpha architecture:
      Size/MD5 checksum:  4577314 574567f7d5ff0c730d7c8403da284d62

  ARM architecture:
      Size/MD5 checksum:  4566364 e9cc7274596bd612b85b832945d4fedc

  Intel IA-32 architecture:
      Size/MD5 checksum:  4549436 adcaa080b69de7c3d7de5d5c58bd2ee6

  Intel IA-64 architecture:
      Size/MD5 checksum:  4594976 ff8e34b0df2d5548918698972ae71ac4

  HP Precision architecture:
      Size/MD5 checksum:  4590474 68576eb8887b9bda98afc3548704d491

  Motorola 680x0 architecture:
      Size/MD5 checksum:  4545894 419dcce4d28053e9527888f064dd9a9d

  Big endian MIPS architecture:
      Size/MD5 checksum:  4557002 70955d5fd0205214a4add453ebda3c9c

  Little endian MIPS architecture:
      Size/MD5 checksum:  4555974 81e127f1ebecb1519ccc08472909a6cc

  PowerPC architecture:
      Size/MD5 checksum:  4548730 7d99eb0b961e83cf9067355c39ba656b

  IBM S/390 architecture:
      Size/MD5 checksum:  4544774 172e282c5c27a5d12a2e3b709b7e89c2

  Sun Sparc architecture:
      Size/MD5 checksum:  4546018 f6d5b53efb642de658498c091884ff7e

  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
< Prev   Next >


Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
Feds Charged With Stealing Money During Silk Road Investigation
EFF questions US government's software flaw disclosure policy
Hotel Router Vulnerability A Reminder Of Untrusted WiFi Risks
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2015 Guardian Digital, Inc. All rights reserved.