<define-tag pagetitle>DSA-1668-1 hf</define-tag>
<define-tag report_date>2008-11-22</define-tag>
<define-tag secrefs>CVE-2008-2378 Bug#504182</define-tag>
<define-tag packages>hf</define-tag>
<define-tag isvulnerable>yes</define-tag>
<define-tag fixed>yes</define-tag>
#use wml::debian::security
<h3>Debian GNU/Linux 4.0 (etch)</h3>
Debian (stable)
<dt>HP Precision:
<dt>Intel IA-32:
<dt>Intel IA-64:
<dt>Big-endian MIPS:
<dt>Little-endian MIPS:
<dt>IBM S/390:
<dt>Sun Sparc:
<p><md5sums /></p>
<define-tag description>programming error</define-tag>
<define-tag moreinfo>
<p>Steve Kemp discovered that hf, an amateur-radio protocol suite using
a soundcard as a modem, insecurely tried to execute an external command
which could lead to the elevation of privileges for local users.</p>
<p>For the stable distribution (etch), this problem has been fixed in version
<p>For the unstable distribution (sid), this problem has been fixed in
version 0.8-8.1.</p>
<p>We recommend that you upgrade your hf package.</p>
