|
COMMAND gpm-root local root format string vulnerabilities SYSTEMS AFFECTED gpm-root 1.17.8-18 (previous versions ??) PROBLEM In Debian Security Advisory DSA-095-1 [http://www.debian.org/security/] The package \'gpm\' contains the \'gpm-root\' program, which can be used to create mouse-activated menus on the console. Among other problems, the gpm-root program contains a format string vulnerability, which allows an attacker to gain root privileges. Editors note : -------------- It seems the problem lies in the shell mouse configuration script that wouldn\'t parse command line arguments properly. Take a look at the diff. SOLUTION Patch : http://security.debian.org/dists/stable/updates/main/source/gpm_1.17.8-18.1.diff.gz Use aptget to ugrade binaries