Secunia Logo
Netsikker nu! 2008
 
Debian update for omega-rpg
Secunia Advisory: SA10190
Release Date: 2003-11-11
Popularity: 7,055 views

Critical:
Not critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0932


Description:
Debian has issued updated packages for omega-rpg. These fix a vulnerability, which can be exploited by malicious, local users to escalate their privileges.

The vulnerability is caused due to boundary errors in the handling of command line arguments and environment variables, which can be exploited to execute arbitrary code with group "games" privileges.

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...ga-rpg/omega-rpg_0.90-pa9-7woody1.dsc
Size/MD5 checksum: 616 ec09d79e6db8d2a26b2419118c82b6d9
http://security.debian.org/pool/updat...pg/omega-rpg_0.90-pa9-7woody1.diff.gz
Size/MD5 checksum: 9264 9a1c91a88685a9a3ebbd3d303d9af458
http://security.debian.org/pool/updat...ga-rpg/omega-rpg_0.90-pa9.orig.tar.gz
Size/MD5 checksum: 425670 decf9c9c5e217a243d87c5693069016f

Alpha architecture:

http://security.debian.org/pool/updat.../omega-rpg_0.90-pa9-7woody1_alpha.deb
Size/MD5 checksum: 433086 e0b2fab139c48fd165856261346509ea

ARM architecture:

http://security.debian.org/pool/updat...pg/omega-rpg_0.90-pa9-7woody1_arm.deb
Size/MD5 checksum: 329224 8821937e31ffdeb13ca7707be44f2ee2

Intel IA-32 architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_i386.deb
Size/MD5 checksum: 313176 5f6e8d376c2dcf9eec749a6589410090

Intel IA-64 architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_ia64.deb
Size/MD5 checksum: 499828 aa1d2895cf9bf64ee15e4632286f819c

HP Precision architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_hppa.deb
Size/MD5 checksum: 367390 bf3008b562d94d34af03cbcecc90e99f

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_m68k.deb
Size/MD5 checksum: 295016 70d31cc87a332a44155ef356ad8e41b5

Big endian MIPS architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_mips.deb
Size/MD5 checksum: 373454 39d6c1c8570fe8aae62a9c7e1c970c6a

Little endian MIPS architecture:

http://security.debian.org/pool/updat...omega-rpg_0.90-pa9-7woody1_mipsel.deb
Size/MD5 checksum: 372138 c21602808847f8edf799d7ee4e562899

PowerPC architecture:

http://security.debian.org/pool/updat...mega-rpg_0.90-pa9-7woody1_powerpc.deb
Size/MD5 checksum: 355306 3b6e082c0568bc3e090b017d1366bf97

IBM S/390 architecture:

http://security.debian.org/pool/updat...g/omega-rpg_0.90-pa9-7woody1_s390.deb
Size/MD5 checksum: 330438 90c057f921d7861f3a511b684d22a630

Sun Sparc architecture:

http://security.debian.org/pool/updat.../omega-rpg_0.90-pa9-7woody1_sparc.deb
Size/MD5 checksum: 347386 40762ef4e8f790f1260c7c84bfd24809


-- Debian GNU/Linux unstable alias sid --

Fixed in version 0.90-pa9-11.

Provided and/or discovered by:
Steve Kemp

Original Advisory:
http://www.debian.org/security/2003/dsa-400


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 8
New vulnerabilities: 27
Updated advisories: 11

Highly // 48 views
Opera Multiple Vulnerabilities
Moderately // 77 views
Red Hat update for condor
Moderately // 74 views
Condor Multiple Vulnerabilities
Moderately // 92 views
Gentoo update for wordnet
Moderately // 102 views
Red Hat update for kernel

7th Oct, 2008
New advisories: 19
New vulnerabilities: 68
Updated advisories: 61

Moderately // 469 views
Debian update for php5
Moderately // 365 views
Atarone CMS Multiple Vulnerabilities

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Red Hat update for kernel // 92 views
2. Adobe Flash Player "Clickjacking" Security Bypass Vulnerability // 92 views
3. Gentoo update for wordnet // 83 views
4. Red Hat update for condor // 60 views
5. Debian update for php5 // 59 views
6. Condor Multiple Vulnerabilities // 57 views
7. Hero DVD Player M3U Processing Buffer Overflow Vulnerability // 50 views
8. Zeroboard Multiple Vulnerabilities // 50 views
9. Atarone CMS Multiple Vulnerabilities // 37 views
10. Zeroboard Two Vulnerabilities // 37 views