Package: slim
Version: 1.3.0-2
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: t...@security.debian.org

If scrot is installed, users are able to overwrite arbitrary files in the
filesystem.

Pressing F11 on the slim login screen runs scrot with the root rights to
save a screenshot to /tmp/slim.png. If this file is symlinked to another
location, that location is overwritten instead.

This bug is introduced by debian/patches/slim-conf.patch and hence
Debian-specific - upstream saves the screenshot in the directory that is
only writable by root.


-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (500, 'testing'), (400, 'unstable'), (300, 'experimental')
Architecture: i386 (x86_64)

Kernel: Linux 2.6.30 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages slim depends on:
ii  debconf [debconf-2.0]         1.5.27     Debian configuration management sy
ii  libc6                         2.9-12     GNU C Library: Shared libraries
ii  libgcc1                       1:4.4.0-5  GCC support library
ii  libjpeg62                     6b-14      The Independent JPEG Group's JPEG
ii  libpam0g                      1.0.1-9    Pluggable Authentication Modules l
ii  libpng12-0                    1.2.37-1   PNG library - runtime
ii  libstdc++6                    4.4.0-5    The GNU Standard C++ Library v3
ii  libx11-6                      2:1.2.1-1  X11 client-side library
ii  libxft2                       2.1.13-3   FreeType-based font drawing librar
ii  libxmu6                       2:1.0.4-1  X11 miscellaneous utility library

Versions of packages slim recommends:
ii  gnome-terminal [x-terminal-em 2.26.2-2   The GNOME terminal emulator applic

Versions of packages slim suggests:
pn  scrot                         <none>     (no description available)



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to