Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Linux :: Debian :: dsa-323.htm

noweb - insecure temporary files

Debian Security Advisory

DSA-323-1 noweb -- insecure temporary files

Date Reported:
16 Jun 2003
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CAN-2003-0381.
More information:

Jakob Lell discovered a bug in the 'noroff' script included in noweb whereby a temporary file was created insecurely. During a review, several other instances of this problem were found and fixed. Any of these bugs could be exploited by a local user to overwrite arbitrary files owned by the user invoking the script.

For the stable distribution (woody) these problems have been fixed in version 2.9a-7.3.

For old stable distribution (potato) this problem has been fixed in version 2.9a-5.1.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you update your noweb package.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Intel IA-32:

Debian GNU/Linux 3.0 (woody)

Intel IA-32:
Motorola 680x0:
Big endian MIPS:

MD5 checksums of the listed files are available in the original advisory.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH