Debian Security Advisory

DSA-927-2 tkdiff -- insecure temporary file

Date Reported:
27 Dec 2005
Affected Packages:
tkdiff
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2005-3343.
More information:

The last update of tkdiff contained a programming error which is fixed by this version.  For completeness we're adding the original advisory text:

Javier Fernández-Sanguino Peña from the Debian Security Audit project discovered that tkdiff, a graphical side by side "diff" utility, creates temporary files in an insecure fashion.

For the old stable distribution (woody) this problem has been fixed in version 3.08-3woody1.

For the stable distribution (sarge) this problem has been fixed in version 4.0.2-1sarge1.

For the unstable distribution (sid) this problem has been fixed in version 4.0.2-4.

We recommend that you upgrade your tkdiff package.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody1.dsc
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody0.diff.gz
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_3.08-3woody1_all.deb

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1.dsc
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1.diff.gz
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/t/tkdiff/tkdiff_4.0.2-1sarge1_all.deb

MD5 checksums of the listed files are available in the original advisory.

MD5 checksums of the listed files are available in the revised advisory.