Säkerhetsbulletin från Debian

DSA-037-1 Athena Widget replacement libraries -- osäker hantering av temporära filer

Rapporterat den:
2001-03-07
Berörda paket:
nextaw
xaw3d
xaw95
Sårbara:
Ja
Referenser i säkerhetsdatabaser:
För närvarande är inga ytterligare referenser till externa säkerhetsdatabaser tillgängliga.
Ytterligare information:
Det har rapproterats att AsciiSrc- och MultiSrc-grafikelementen i Athena-grafikelementsbiblioteket hanterade temporärfiler osäkert. Joey Hess har anpassat felrättelsen från XFree86 till dessa Xaw-ersättningsbibliotek. Rättelserna är tillgängliga i nextaw 0.5.1-34potato1, xaw3d 1.3-6.9potato1 och xaw95 1.1-4.6potato1.
Rättat i:

Debian 2.2 (potato)

Källkod:
http://security.debian.org/dists/stable/updates/main/source/nextaw_0.5.1-34potato1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/nextaw_0.5.1-34potato1.dsc
http://security.debian.org/dists/stable/updates/main/source/nextaw_0.5.1.orig.tar.gz
http://security.debian.org/dists/stable/updates/main/source/xaw3d_1.3-6.9potato1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/xaw3d_1.3-6.9potato1.dsc
http://security.debian.org/dists/stable/updates/main/source/xaw3d_1.3.orig.tar.gz
http://security.debian.org/dists/stable/updates/main/source/xaw95_1.1-4.6potato1.diff.gz
http://security.debian.org/dists/stable/updates/main/source/xaw95_1.1-4.6potato1.dsc
http://security.debian.org/dists/stable/updates/main/source/xaw95_1.1.orig.tar.gz
i386:
http://security.debian.org/dists/stable/updates/main/binary-i386/nextaw_0.5.1-34potato1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/nextawg_0.5.1-34potato1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xaw3d_1.3-6.9potato1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xaw3dg-dev_1.3-6.9potato1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xaw3dg_1.3-6.9potato1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/xaw95g_1.1-4.6potato1_i386.deb
m68k:
http://security.debian.org/dists/stable/updates/main/binary-m68k/nextaw_0.5.1-34potato1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/nextawg_0.5.1-34potato1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xaw3d_1.3-6.9potato1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xaw3dg-dev_1.3-6.9potato1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xaw3dg_1.3-6.9potato1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/xaw95g_1.1-4.6potato1_m68k.deb