SHARE
Facebook X Pinterest WhatsApp

Security vulnerability in ‘fte’ found.

Written By
thumbnail
Web Webster
Web Webster
Dec 7, 1998
From: Wichert Akkerman <wichert@cs.leidenuniv.nl>

We have found that the fte package as supplied in our slink (frozen)
and potato (unstable) archives does not drop its root priviliges
after initializing the virtual console device. This allows all users
to read and write files with root priviliges, and execute all programs
as root.

A new package (version 0.46b-4.1) has been uploaded to fix this problem. 

We recommend that you upgrade your fte package immediately.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

Debian GNU/Linux 2.0 alias hamm
-------------------------------

  The fte package in this release does not suffer from this problem.


Debian GNU/Linux 2.1 alias slink (not released yet)
---------------------------------------------------

  Source archives:
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.diff.gz
      MD5 checksum: 44c60f6b5b55c80f7634eb405f3707e5
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5-4.1.dsc
      MD5 checksum: e8991ea4fe2e298b57432e80dc5fd0b8
    ftp://ftp.debian.org/debian/dists/slink/main/source/editors/fte_0.46b5.orig.tar.gz
      MD5 checksum: 255f2f8cd2c210b497fdcdb0b9f964ed

  Intel architecture:
    ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte-console_0.46b5-4.1.deb
      MD5 checksum: 0d3d146749f68b11f6aed19d64161bbe
    ftp://ftp.debian.org/debian/dists/slink/main/binary-i386/editors/fte_0.46b5-4.1.deb
      MD5 checksum: 39a33e02915d6cc594b9170d0fc9b0f8

  Motorola 680x0 architecture:
    ftp://ftp.debian.org/debian/dists/slink/main/binary-m68k/editors/fte-console_0.46b5-4.1_m68k.deb
      MD5 checksum: 117675708c4b3b1afbdbac5e63c997b0
    ftp://ftp.debian.org/debian/dists/slink/main/binary-m68k/editors/fte_0.46b5-4.1_m68k.deb
      MD5 checksum: 9c7fb9a6f7b89025afb8cfa63a4da0ec

For not yet released architectures please refer to the appropriate
directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ .

--
Debian GNU/Linux      .   Security Managers      .   security@debian.org
              debian-security-announce@lists.debian.org
  Christian Hudon     .     Wichert Akkerman     .     Martin Schulze
<chrish@debian.org>   .   <wakkerma@debian.org>  .   <joey@debian.org>

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

A Thorough Approach to Improve the Privacy and Security of Your Linux PC
Damien
Oct 24, 2024
Several Russian Maintainers Removed From Linux Kernel Due To Compliance Concerns
Senthil Kumar
Oct 23, 2024
OpenSSH Splits Again: New Authentication Binary Unveiled
Bobby Borisov
Oct 16, 2024
13 Best Free and Open Source Anti-Malware Tools
webmaster
Oct 14, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.