Debian Security Advisory

DSA-633-1 bmv -- insecure temporary file

Date Reported:
11 Jan 2005
Affected Packages:
bmv
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2003-0014.
More information:

Peter Samuelson, upstream maintainer of bmv, a PostScript viewer for SVGAlib, discovered that temporary files are created in an insecure fashion. A malicious local user could cause arbitrary files to be overwritten by a symlink attack.

For the stable distribution (woody) this problem has been fixed in version 1.2-14.2.

For the unstable distribution (sid) this problem has been fixed in version 1.2-17.

We recommend that you upgrade your bmv packages.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2-14.2.dsc
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2-14.2.diff.gz
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2.orig.tar.gz
Intel IA-32:
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2-14.2_i386.deb

MD5 checksums of the listed files are available in the original advisory.