Debian Security Advisory: New version of make released | Linux Today

Debian Security Advisory: New version of make released

Written By
Web Webster
Web Webster
Feb 22, 2000

Date: Mon, 21 Feb 2000 10:38:30 -0800
From: Aleph One aleph1@UNDERGROUND.ORG
To: BUGTRAQ@SECURITYFOCUS.COM
Subject: [Debian] New version of make released


Debian Security Advisory security@debian.org
http://www.debian.org/security/
Wichert Akkerman
February 20, 2000


Package: make
Vulnerability type: symlink attack
Debian-specific: no

The make package as shipped in Debian GNU/Linux 2.1 is
vulnerable to a race condition that can be exploited with a symlink
attack. make used mktemp while creating temporary files in /tmp.
and that is a known potential security hole, as documented in the
man page of mktemp.

This has been fixed in version 3.77-5slink. We recommend you
upgrade your make package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink


This version of Debian was released only for Intel ia32, the
Motorola 680×0, the alpha and the Sun sparc architecture.

Source archives:

http://security.debian.org/dists/stable/updates/source/make_3.77.orig.tar.gz

MD5Dum: b8264b1f8579d810a6de5db634aeafe4

http://security.debian.org/dists/stable/updates/source/make_3.77-5slink.diff.gz

MD5Dum: 4cf0016add45fb2bb1986cdcf3df4df2

http://security.debian.org/dists/stable/updates/source/make_3.77-5slink.dsc

MD5Dum: 351d1492a17cd4b38f522037a2714a86

Alpha architecture:

http://security.debian.org/dists/stable/updates/binary-alpha/make_3.77-5slink_alpha.deb

MD5Dum: a253a6d897edbc163595dbedefbfd8bc

Intel ia32 architecture:

http://security.debian.org/dists/stable/updates/binary-i386/make_3.77-5slink_i386.deb

MD5Dum: 78367bf9f0d309d732eaa57bc9008462

Motorola 680×0 architecture:

http://security.debian.org/dists/stable/updates/binary-m68k/make_3.77-5slink_m68k.deb

MD5Dum: 678955fdde1a099db1ac7719e7026cbc

Sun Sparc architecture:

http://security.debian.org/dists/stable/updates/binary-sparc/make_3.77-5slink_sparc.deb

MD5Dum: 87b8ff54ca2f9c1113349da5cf591331

Architecture independent archive (for completeness):

http://security.debian.org/dists/stable/updates/binary-all/make-doc_3.77-5slink_all.deb

MD5Dum: cb63706913f8202c52ead1031a8494dc

These files will be moved into
ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/
soon.

For not yet released architectures please refer to the
appropriate directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/
.

– —


For apt-get: deb http://security.debian.org/
stable updates
For dpkg-ftp: ftp://security.debian.org/debian-security
dists/stable/updates
Mailing list: debian-security-announce@lists.debian.org

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.