Debian Security Advisory 1945 gforge – symlink attack

38
Article Source Debian Security Advisories
December 2, 2009, 4:00 pm

Sylvain Beucler discovered that gforge, a collaborative development tool, is prone to a symlink attack, which allows local users to perform a denial of service attack by overwriting arbitrary files.

The oldstable distribution (etch), this problem has been fixed in version 4.5.14-22etch13.

For the stable distribution (lenny), this problem has been fixed in version 4.7~rc2-7lenny3.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 4.8.2-1…

Read More