Articles / Debian: New link-grammar pa…

Debian: New link-grammar packages fix execution of code

Alin Rad Pop discovered that link-grammar, Carnegie Mellon University's link grammar parser for English, performed insufficient validation within its tokenizer, which could allow a malicious input file to execute arbitrary code.
Debian Security Advisory DSA-1432-1                                       Steve Kemp
December 16, 2007           
Package        : link-grammar
Vulnerability  : buffer overflow
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2007-5395
Debian Bug     : 450695

Alin Rad Pop discovered that link-grammar, Carnegie Mellon University's
link grammar parser for English, performed insufficient validation within
its tokenizer, which could allow a malicious input file to execute
arbitrary code.

For the stable distribution (etch), this problem has been fixed in version

For the old stable distribution (sarge), this package was not present.

For the unstable distribution (sid), this problem was fixed in version

We recommend that you upgrade your link-grammar package.

Debian GNU/Linux 4.0 alias etch
 These files will probably be moved into the stable distribution on
 its next update.

