Title : Debian Security Update Fixes Bzip2 Race Condition Vulnerability VUPEN ID : VUPEN/ADV-2005-0652 CVE ID : CVE-2005-0953 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-05-30
Technical Description
Debian has released a security patch to correct a vulnerability identified in bzip2. This flaw is due to a race condition error in the file permission restore code of bunzip2, which could be exploited by local attackers to gain read/write access to files of other users. For additional information, see : VUPEN/ADV-2005-0560
Debian GNU/Linux 3.0 (woody) - Upgrade to version 1.0.2-1.woody2
Debian GNU/Linux unstable (sid) - Upgrade to version 1.0.2-6
Debian GNU/Linux testing (sarge) - Upgrade to version 1.0.2-6 References