TUCoPS :: Linux :: Debian :: dsa-1081.txt

wmtv symlink vulnerability - Debian Security Advisory DSA 108-1

Debian Security Advisory DSA 108-1                                        Martin Schulze
February 7th, 2002  
Package        : wmtv
Vulnerability  : symlink vulnerability
Problem-Type   : local
Debian-specific: no

Nicolas Boullis found some security problems in the wmtv package (a
dockable video4linux TV player for windowmaker) which is distributed
in Debian GNU/Linux 2.2.  With the current version of wmtv, the
configuration file is written back as the superuser, and without any
further checks.  A mailicious user might use that to damage important

This problem has been fixed in version 0.6.5-2potato2 for the stable
distribution by dropping privileges as soon as possible and only
regaining them where required.  In the current testing/unstable
distribution this problem has been fixed in version 0.6.5-9 and above
by not requiring privileges anymore.  Both contain fixes for two
potential buffer overflows as well.

We recommend that you upgrade your wmtv packages immediately.

Debian GNU/Linux 2.2 alias potato
