DSA 1643-1: New feta packages fix denial of service
Posted on: 10/05/2008 01:00 PM

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:

Debian Security Advisory DSA-1643-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
October 05, 2008 http://www.debian.org/security/faq
Package : feta
Vulnerability : insecure temp file handling
Problem type : local
Debian-specific: no
CVE Id(s) : CVE-2008-4440
Debian Bug : 496397

Dmitry E. Oboukhov discovered that the "to-upgrade" plugin of Feta,
a simpler interface to APT, dpkg, and other Debian package tools
creates temporary files insecurely, which may lead to local denial
of service through symlink attacks.

For the stable distribution (etch), this problem has been fixed in
version 1.4.15+etch1.

For the unstable distribution (sid), this problem has been fixed in
version 1.4.16+nmu1.

We recommend that you upgrade your feta package.

Debian GNU/Linux 4.0 alias etch
Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

Size/MD5 checksum: 545 87c8cdfc722b149eefc2c4cc1e05c868
Size/MD5 checksum: 52134 27b5bc566e7f42a5b79dd8ef67013b8d

Architecture independent packages:

Size/MD5 checksum: 47708 8133fddc8dc30973c5fcb3368292b1fb

These files will probably be moved into the stable distribution on
its next update.

