6439784 2001-05-02 11:24 +0200  /22 rader/ Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE>
Sänt av: joel@lysator.liu.se
Importerad: 2001-05-02  18:20  av Brevbäraren
Extern mottagare: BUGTRAQ@SECURITYFOCUS.COM
Externa svar till: Florian.Weimer@RUS.UNI-STUTTGART.DE
Mottagare: Bugtraq (import) <16873>
Kommentar till text 6402418 av  <debian-security-announce@LISTS.DEBIAN.ORG>
Ärende: Re: [SECURITY] [DSA 052-1] New sendfile packages fix root exploit
------------------------------------------------------------
From: Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE>
To: BUGTRAQ@SECURITYFOCUS.COM
Message-ID: <tgk840gl3i.fsf@mercury.rus.uni-stuttgart.de>

debian-security-announce@LISTS.DEBIAN.ORG writes:

> Package        : sendfile
> Vulnerability  : broken privileges dropping
> Problem-Type   : local root exploit
> Debian-specific: no

The author, Ulli Horlacher, released an updated version of sendfile
which corrects these problems a few months ago.  It's available from:

ftp://ftp.belwue.de/pub/unix/sendfile/

--
Florian Weimer 	                  Florian.Weimer@RUS.Uni-Stuttgart.DE
University of Stuttgart           http://cert.uni-stuttgart.de/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898
(6439784) /Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE>/