TUCoPS :: Linux :: Debian :: dsa-0951.txt

gpm local root vulnerability - Debian Security Advisory DSA 095-1

Debian Security Advisory DSA-095-1                             Robert van der Meulen
December 27, 2001
Package        : gpm
Problem type   : local root vulnerability
Debian-specific: no

The package 'gpm' contains the 'gpm-root' program, which can be used to
create mouse-activated menus on the console.
Among other problems, the gpm-root program contains a format string
vulnerability, which allows an attacker to gain root privileges.

This has been fixed in version 1.17.8-18.1, and we recommend that you upgrade
your 1.17.8-18 package immediately.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

Debian GNU/Linux 2.2 alias potato
  Potato was released for alpha, arm, i386, m68k, powerpc and sparc.

  Source archives:
apt-get: deb stable/updates main
dpkg-ftp: dists/stable/updates/main
Mailing list:
