• [SECURITY] [DSA 2791-1] tryton-client security update

    From Florian Weimer@1:229/2 to All on Mon Nov 4 07:40:02 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2791-1 [email protected] http://www.debian.org/security/ Florian Weimer November 04, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : tryton-client
    Vulnerability : missing input sanitization
    Problem type : remote
    Debian-specific: no

    Cedric Krier discovered that the Tryton client does not sanitize the
    file extension supplied by the server when processing reports. As a
    result, a malicious server could send a report with a crafted file
    extension that causes the client to write any local file to which the
    user running the client has write access.

    For the oldstable distribution (squeeze), this problem has been fixed in version 1.6.1-1+deb6u1.

    For the stable distribution (wheezy), this problem has been fixed in
    version 2.2.3-1+deb7u1.

    We recommend that you upgrade your tryton-client packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJSd0JkAAoJEL97/wQC1SS+yxIIAKhE710knodmQwpAoCSobSwp 3cK7RK7PIMkiyAfLnNi646cU0xXGWydgwydxvm1VyULBtsBbaOaEXzOu8j2eOYVR WQeUEy3kiDGE3J38QUzaf0MGejZI3jZQRERkYIxEOkEvsHZqZYLLe+BOvOt1Nz2T vMMRqCjcAN+k1eE271tL9omWZxpsVCFG0uIGwfTmpCgf7QGKqnlnuMfrpeDQ+7/3 8VOE6EOrIBbFdXeXxW/TKM94Z8HGGkpU+GUJ2FiMyF0q0e8e4n2JG0sldnIeM9RF cSrv5550JSSGgCLh3t3JtBTCsvQMGfnPKKdvx781vIz0inTgXy2SFAYaUukBPks=
    =ZvvC
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)