Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1945-1] New gforge packages fix denial of service (1/2)

    From Steffen Joeris@1:229/2 to All on Thu Dec 3 13:50:02 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1945-1 [email protected] http://www.debian.org/security/ Steffen Joeris
    December 03, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : gforge
    Vulnerability : symlink attack
    Problem type : local
    Debian-specific: no
    CVE ID : CVE-2009-3304

    Sylvain Beucler discovered that gforge, a collaborative development
    tool, is prone to a symlink attack, which allows local users to perform
    a denial of service attack by overwriting arbitrary files.


    For the stable distribution (lenny), this problem has been fixed in
    version 4.7~rc2-7lenny3.

    The oldstable distribution (etch), this problem has been fixed in
    version 4.5.14-22etch13.

    For the testing distribution (squeeze), this problem will be fixed soon.

    For the unstable distribution (sid), this problem has been fixed in
    version 4.8.2-1.


    We recommend that you upgrade your gforge packages.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Debian (oldstable)
    - ------------------

    Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch13.dsc
    Size/MD5 checksum: 953 a170b517b1d68ca0ad53a1b8b03c3317
    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14.orig.tar.gz
    Size/MD5 checksum: 2161141 e85f82eff84ee073f80a2a52dd32c8a5
    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch13.diff.gz
    Size/MD5 checksum: 204328 33081d2f6a0056b31091360db3002a9f

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-ldap_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 86628 c6b62116a819fa9033335acae8df867d
    http://security.debian.org/pool/updates/main/g/gforge/gforge-common_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 1012268 78dfb2931853c3f89d233cc9510199f2
    http://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 212786 1bc973b449b07020fbef4519fc8e074e
    http://security.debian.org/pool/updates/main/g/gforge/gforge-web-apache_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 705446 286aba34673375cb8763765fd241d791
    http://security.debian.org/pool/updates/main/g/gforge/gforge-ftp-proftpd_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 86344 394f14f010e9de88145cc3251e7e8982
    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 80562 52133da4596347d8c05e37643a959435
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 88808 72ad3b9f7d9d1f8732551a99b5e74471
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-courier_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 76368 c7ba219bac6560994c07dfb639801c99
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim4_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 89414 095ca81a4671193cd5d822e967d36684
    http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-postgresql_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 87434 8d960c7671eac2a480a43cd948a98d7d
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 88904 8d3692ecc555ca40558d50333bf543a9
    http://security.debian.org/pool/updates/main/g/gforge/gforge-lists-mailman_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 82386 3bc6d055f6eb74edfd23ca8dbfb8fa3e
    http://security.debian.org/pool/updates/main/g/gforge/gforge-ldap-openldap_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 95738 beee5393efe02def8071a78a3707244c
    http://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_4.5.14-22etch13_all.deb
    Size/MD5 checksum: 104062 a70e01f8055201519b14718555023abb


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Debian (stable)
    - ---------------

    Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.7~rc2-7lenny3.diff.gz
    Size/MD5 checksum: 106204 cd0b909a3d31bc9a0649a6f16bd54478
    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.7~rc2-7lenny3.dsc
    Size/MD5 checksum: 1487 24e0ca65d2b17abd34328dd21994dd9a
    http://security.debian.org/pool/updates/main/g/gforge/gforge_4.7~rc2.orig.tar.gz
    Size/MD5 checksum: 10225404 bd24808ce79363d4c7c529778f6f5324

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/g/gforge/gforge-plugin-mediawiki_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 213590 e252b1c97bda1c020e89c30e5faacac8
    http://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 106960 acdbec4148e84ccfaf6993cbbddf9dd2
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-courier_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 88822 cbc85f52ffca569001a0bb7b0ec8d3dc
    http://security.debian.org/pool/updates/main/g/gforge/gforge-shell-postgresql_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 95136 452be3de57f17866b0de3d3f19c0072f
    http://security.debian.org/pool/updates/main/g/gforge/gforge-common_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 1112248 25679e24ad18e5a910a8d43808ebac13
    http://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 231056 3523089618564cec5703a4f8bf8eaa6e
    http://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_4.7~rc2-7lenny3_all.deb
    Size/MD5 checksum: 101588 30efdc5330cf09bf91afb2fe12c58db3

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Sun Jun 7 20:58:28 2026
      from Wales, Uk via Telnet
    • Michal Wronka
      Sun Jun 7 19:26:28 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 24:41:40
    Calls: 12,106
    Calls today: 6
    Files: 15,006
    Messages: 6,518,168

© >>> Magnum BBS <<<, 2026