Debian Security Advisory
DSA-927-2 tkdiff -- insecure temporary file
- Date Reported:
- 27 Dec 2005
- Affected Packages:
- tkdiff
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2005-3343.
- More information:
-
The last update of tkdiff contained a programming error which is fixed by this version. For completeness we're adding the original advisory text:
Javier Fernández-Sanguino Peña from the Debian Security Audit project discovered that tkdiff, a graphical side by side "diff" utility, creates temporary files in an insecure fashion.
For the old stable distribution (woody) this problem has been fixed in version 3.08-3woody1.
For the stable distribution (sarge) this problem has been fixed in version 4.0.2-1sarge1.
For the unstable distribution (sid) this problem has been fixed in version 4.0.2-4.
We recommend that you upgrade your tkdiff package.
- Fixed in:
-
Debian GNU/Linux 3.0 (woody)
- Source:
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody1.dsc
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody0.diff.gz
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08.orig.tar.gz
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody0.diff.gz
- Architecture-independent component:
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody1_all.deb
Debian GNU/Linux 3.1 (sarge)
- Source:
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1.dsc
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1.diff.gz
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2.orig.tar.gz
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1.diff.gz
- Architecture-independent component:
- http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1_all.deb
MD5 checksums of the listed files are available in the original advisory.
MD5 checksums of the listed files are available in the revised advisory.