[CVE-2007-6211] sing in debian is vulnerable

Bug #173948 reported by Stephan Rügamer
256
Affects Status Importance Assigned to Milestone
sing (Debian)
Fix Released
Unknown
sing (Ubuntu)
Fix Released
Undecided
William Grant
Dapper
Fix Released
Undecided
Stephan Rügamer
Edgy
Fix Released
Undecided
Stephan Rügamer
Feisty
Fix Released
Undecided
Stephan Rügamer
Gutsy
Fix Released
Undecided
Stephan Rügamer
Hardy
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: sing

Dear Colleagues,

Send Nasty ICMP Garbage (sing) on Debian GNU/Linux allows local users
to append to arbitrary files and gain privileges via the -L (output
log file) option.

The very same version we have in Ubuntu.

Changed in sing:
assignee: nobody → shermann
status: New → In Progress
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
William Grant (wgrant)
Changed in sing:
assignee: shermann → fujitsu
assignee: nobody → shermann
status: New → In Progress
assignee: nobody → shermann
status: New → In Progress
assignee: nobody → shermann
status: New → In Progress
assignee: nobody → shermann
status: New → In Progress
Revision history for this message
William Grant (wgrant) wrote :

sing (1.1-15ubuntu1) hardy; urgency=low

  * SECURITY UPDATE: Privilege escalation via file appending. (LP: #173948)
  * parser.c: Change UID to that of the running user before opening files.
    Patch from Debian.
  * References
    CVE-2007-6211

 -- William Grant <email address hidden> Wed, 05 Dec 2007 18:38:37 +1100

Changed in sing:
status: In Progress → Fix Released
Changed in sing:
status: Unknown → Fix Released
Revision history for this message
Kees Cook (kees) wrote :

Thanks for the updates! This is building now and should publish shortly.

Changed in sing:
status: In Progress → Fix Committed
status: In Progress → Fix Committed
status: In Progress → Fix Committed
status: In Progress → Fix Committed
Kees Cook (kees)
Changed in sing:
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.