[Bug 320082] Re: [CVE-2008-2378] - Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan horse

Kees Cook kees at ubuntu.com
Sun Apr 19 15:48:51 UTC 2009


hf (0.7.3-2ubuntu0.1) dapper-security; urgency=low

  * SECURITY UPDATE: Fix local root security hole that is caused by an 
    insecure call to the system function, thanks Steve Kemp. (LP: #320082)
    - Patch from Debian applied inline. (Modified for 0.7.3)
    - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504182
    - CVE-2008-2378

 -- Stefan Lesicnik <stefan at lsd.co.za>  Thu, 22 Jan 2009 18:13:36 +0200


** Changed in: hf (Ubuntu Dapper)
       Status: Fix Committed => Fix Released

-- 
[CVE-2008-2378] - Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan horse
https://bugs.launchpad.net/bugs/320082
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs




More information about the universe-bugs mailing list