Get Certified! Ubuntu Online Training

News

USN-457-1: elinks vulnerability

=========================================================== Ubuntu Security Notice USN-457-1 May 07, 2007 elinks vulnerability CVE-2007-2027 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: elinks 0.10.6-1ubuntu3.1 Ubuntu 6.10: elinks 0.11.1-1ubuntu2.1 Ubuntu 7.04: elinks 0.11.1-1.2ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Arnaud Giersch discovered that elinks incorrectly attempted to load gettext catalogs from a relative path. If a user were tricked into running elinks from a specific directory, a local attacker could execute code with user privileges.