Lucene search

K
osvGoogleOSV:DSA-615-1
HistoryDec 22, 2004 - 12:00 a.m.

debmake - insecure temporary file

2004-12-2200:00:00
Google
osv.dev
5

0.0004 Low

EPSS

Percentile

5.1%

Javier FernĂĄndez-Sanguino PeĂąa from the Debian Security Audit Project
noticed that the debstd script from
debmake, a deprecated helper package for Debian packaging, created
temporary directories in an insecure manner. This can be exploited by
a malicious user to overwrite arbitrary files owned by the victim.

For the stable distribution (woody) this problem has been fixed in
version 3.6.10.woody.1.

For the unstable distribution (sid) this problem has been fixed in
version 3.7.7.

We recommend that you upgrade your debmake package.