USN-457-1: elinks vulnerability
7 May 2007
elinks vulnerability
Releases
Details
Arnaud Giersch discovered that elinks incorrectly attempted to load
gettext catalogs from a relative path. If a user were tricked into
running elinks from a specific directory, a local attacker could execute
code with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.04
-
elinks
-
0.11.1-1.2ubuntu2.1
Ubuntu 6.10
-
elinks
-
0.11.1-1ubuntu2.1
Ubuntu 6.06
-
elinks
-
0.10.6-1ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.