-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Fri, 02 Jan 2004 19:37:26 +0000 Source: vbox3 Binary: vbox3 Architecture: source i386 Version: 0.1.7.1 Distribution: stable Urgency: high Maintainer: Gerrit Pape Changed-By: Gerrit Pape Description: vbox3 - voice response system for isdn4linux Changes: vbox3 (0.1.7.1) stable; urgency=high . * vboxgetty/voice.c: bug: permissions were not dropped accurately before running user-controlled tclscript; a user was able to gain root permissions through the tclscript. fix: fork(), setgid(), setuid() before running tclscript, and let main process wait for child. See bug #218288. Files: d3a0b979c0e9d6bce084aa7de30c7014 506 utils extra vbox3_0.1.7.1.dsc a38f00e38463b13cc055a7a19eca60e9 105031 utils extra vbox3_0.1.7.1.tar.gz bb9a8a71d32904d51394c300b75111b7 32328 utils extra vbox3_0.1.7.1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/9pLhGJoyQbxwpv8RAmmHAJ4jkwtQmavTDO2XCRxLtMb5DLNi+QCfR0gH 7WCT1uMHGvBf3avE4VQcFOI= =1Vdv -----END PGP SIGNATURE-----