Secunia Logo  


Secunia PSI WorldMap
 
Orville Write Environment Variable Privilege Escalation Vulnerability
Secunia Advisory: SA9085
Release Date: 2003-06-20
Popularity: 8,294 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0

Software:Orville write 2.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Update to version 2.54:
http://www.unixpapa.com/software/orville-write-2.54.tar.gz

Debian has issued updated packages:

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...-write/orville-write_2.53-4woody1.dsc
Size/MD5 checksum: 589 170c84e5c499f942ca625cb0f10e2bbe
http://security.debian.org/pool/updat...te/orville-write_2.53-4woody1.diff.gz
Size/MD5 checksum: 4882 f9147a6f6c6d69e954d024fbaf789ecf
http://security.debian.org/pool/updat...-write/orville-write_2.53.orig.tar.gz
Size/MD5 checksum: 75717 9dafdab825157df8377ce67a3c0eb2a5

Alpha architecture:

http://security.debian.org/pool/updat.../orville-write_2.53-4woody1_alpha.deb
Size/MD5 checksum: 63424 aa2124137efcafbf9baceb196a942564

ARM architecture:

http://security.debian.org/pool/updat...te/orville-write_2.53-4woody1_arm.deb
Size/MD5 checksum: 52108 89c8970e2523fe6a98a053ae9bb1e997

Intel IA-32 architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_i386.deb
Size/MD5 checksum: 51938 fb5d8e11b58013abd377e9425a8aab39

Intel IA-64 architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_ia64.deb
Size/MD5 checksum: 71988 df14d6a8f997ceec1acb348a8cb92b56

HP Precision architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_hppa.deb
Size/MD5 checksum: 58534 b384d176de75d907dd08e723f701d6ed

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_m68k.deb
Size/MD5 checksum: 51098 ac0307daa1d4c6abfe7810a85fd49589

Big endian MIPS architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_mips.deb
Size/MD5 checksum: 57830 4507261a670f4c50605bb84170a705b2

Little endian MIPS architecture:

http://security.debian.org/pool/updat...orville-write_2.53-4woody1_mipsel.deb
Size/MD5 checksum: 57154 130d5d0d7e6d55145fe690f0de7d2a8e

PowerPC architecture:

http://security.debian.org/pool/updat...rville-write_2.53-4woody1_powerpc.deb
Size/MD5 checksum: 51760 20d239c6aca202dc4a5bec07ba772219

IBM S/390 architecture:

http://security.debian.org/pool/updat...e/orville-write_2.53-4woody1_s390.deb
Size/MD5 checksum: 54224 cb98e4b5fff39313b865978647f74ee5

Sun Sparc architecture:

http://security.debian.org/pool/updat.../orville-write_2.53-4woody1_sparc.deb
Size/MD5 checksum: 60146 a5714352ef8e50bdbede1600afce7041


-- Debian GNU/Linux unstable alias sid --

Reportedly, this will be fixed soon.

Provided and/or discovered by:
Steve Kemp

Original Advisory:
http://www.debian.org/security/2003/dsa-326

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

11th Nov, 2009
New advisories: 18
New vulnerabilities: 40
Updated advisories: 39

Less // 148 views
Fedora update for dhcp
Moderately // 153 views
Fedora update for ocaml-camlimages
Moderately // 152 views
Fedora update for libvorbis
Less // 154 views
Fedora update for wordpress-mu
Highly // 206 views
Red Hat update for java-1.5.0-sun

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 79 views
2. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 73 views
3. Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities // 47 views
4. Adobe Flash Player Multiple Vulnerabilities // 40 views
5. Microsoft XML Core Services Multiple Vulnerabilities // 38 views
6. Google Chrome Two Vulnerabilities // 29 views
7. Red Hat update for java-1.5.0-sun // 27 views
8. Adobe Reader/Acrobat Multiple Vulnerabilities // 27 views
9. Citrix XenApp Online Plug-in / Receiver Certificate Spoofing Vulnerability // 24 views
10. Citrix Secure Gateway TLS Session Renegotiation Plaintext Injection // 24 views