Debian Security Advisory

DSA-107-1 jgroff -- format print vulnerability

Date Reported:
30 Jan 2002
Affected Packages:
Security database references:
No other external database security references currently available.
More information:
Basically, this is the same Security Advisory as DSA 072-1, but for jgroff instead of groff. The package jgroff contains a version derived from groff that has Japanese character sets enabled. This package is available only in the stable release of Debian, patches for Japanese support have been merged into the main groff package.

The old advisory said:

Zenith Parse found a security problem in groff (the GNU version of troff). The pic command was vulnerable to a printf format attack which made it possible to circumvent the `-S' option and execute arbitrary code.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Intel ia32:
Motorola 680x0:
Sun Sparc:

MD5 checksums of the listed files are available in the original advisory.