TEMP-0324913-425151

NameTEMP-0324913-425151
Descriptioncplay - still unsafe temporary file handling vulnerable to symlink attacks
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs324913

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cplay (PTS)jessie1.49-10fixed
stretch1.50-1fixed
buster1.50-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cplaysourcewoody(not affected)
cplaysource(unstable)1.49-8low324913

Notes

[woody] - cplay <not-affected> (CPLAY_TMP doesn't exist in this version)
[sarge] - cplay <no-dsa> (Hardly exploitable)

Search for package or bug name: Reporting problems