TEMP-0324913-425151

NameTEMP-0324913-425151
Descriptioncplay - still unsafe temporary file handling vulnerable to symlink attacks
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs324913

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cplay (PTS)wheezy, jessie1.49-10fixed
buster, sid, stretch1.50-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cplaysource(unstable)1.49-8low324913
cplaysourcewoody(not affected)

Notes

[woody] - cplay <not-affected> (CPLAY_TMP doesn't exist in this version)
[sarge] - cplay <no-dsa> (Hardly exploitable)

Search for package or bug name: Reporting problems