TUCoPS :: Linux :: Debian :: dsa-1561.txt

epic4-script-light arbitrary script execution - Debian Security Advisory DSA 156-1

Debian Security Advisory DSA 156-1                                        Martin Schulze
August 22th, 2002             
Package        : epic4-script-light
Vulnerability  : arbitrary script execution
Problem-Type   : remote
Debian-specific: no

All versions of the EPIC script Light prior to 2.7.30p5 (on the 2.7
branch) and prior to 2.8pre10 (on the 2.8 branch) running on any
platform are vulnerable to a remotely-exploitable bug, which can lead
to nearly arbitrary code execution.

This problem has been fixed in version 2.7.30p5-1.1 for the current
stable distribution (woody) and in version 2.7.30p5-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the Light package.

We recommend that you upgrade your epic4-script-light package and
restart your IRC client.

Debian GNU/Linux 3.0 alias woody
  Source archives:
