New bsdgames packages fix local privilege escalation
SecurityAlert : 736 CVE : CVE-2006-1744 SecurityRisk : Medium (About) Remote Exploit : No Local Exploit : Yes Exploit Given : No Credit : Moritz Muehlenhoff (jmm debian org) Published : 19.04.2006
Package : bsdgames
Vulnerability : buffer overflow
Problem type : local
Debian-specific: no
Debian Bug : 360989
CVE ID : CVE-2006-1744
A buffer overflow problem has been discovered in sail, a game contained
in the bsdgames package, a collection of classic textual Unix games, which
could lead to games group privilege escalation.
For the old stable distribution (woody) this problem has been fixed in
version 2.13-7woody0.
For the stable distribution (sarge) this problem has been fixed in
version 2.7.59-7sarge1.
For the unstable distribution (sid) this problem has been fixed in
version 2.17-7.
We recommend that you upgrade your bsdgames package.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.0 alias woody
- --------------------------------
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.