Re: [SECURITY] [DSA 557-1] New rp-pppoe packages fix potential root compromise

2004-10-14 Thread Max Vozeler
On Mon, Oct 11, 2004 at 03:57:16PM -0400, Greg Folkert wrote: > On Mon, 2004-10-11 at 21:13 +0200, Nils Rennebarth wrote: > > Martin Schulze wrote: > > > For the unstable distribution (sid) this problem has been fixed in > > > version 3.5-4. > > > > Is there an estimation when the 3.5-4 Version for

Re: [SECURITY] [DSA 557-1] New rp-pppoe packages fix potential root compromise

2004-10-11 Thread Greg Folkert
On Mon, 2004-10-11 at 21:13 +0200, Nils Rennebarth wrote: > Martin Schulze wrote: > > Max Vozeler discovered a vulnerability in pppoe, the PPP over Ethernet > > driver from Roaring Penguin. When the program is running setuid root > > (which is not the case in a default Debian installation), an att

Re: [SECURITY] [DSA 557-1] New rp-pppoe packages fix potential root compromise

2004-10-11 Thread Nils Rennebarth
Martin Schulze wrote: Max Vozeler discovered a vulnerability in pppoe, the PPP over Ethernet driver from Roaring Penguin. When the program is running setuid root (which is not the case in a default Debian installation), an attacker could overwrite any file on the file system. For the stable distri