Hash: SHA512

Package        : tenshi
Version        : 0.13-2+deb7u1
CVE ID         : CVE-2017-11746
Debian Bug     : 871321

Tenshi creates a tenshi.pid file after dropping privileges to a non-root
account, which might allow local users to kill arbitrary processes by
leveraging access to this non-root account for tenshi.pid modification before a
root script executes a "kill `cat /pathname/tenshi.pid`" command.

For Debian 7 "Wheezy", these problems have been fixed in version
0.13-2+deb7u1.

We recommend that you upgrade your tenshi packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1069-1: tenshi security update

August 27, 2017
Tenshi creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root ac...

Summary

For Debian 7 "Wheezy", these problems have been fixed in version
0.13-2+deb7u1.

We recommend that you upgrade your tenshi packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : tenshi
Version : 0.13-2+deb7u1
CVE ID : CVE-2017-11746
Debian Bug : 871321

Related News