DSA-1676-1 flamethrower -- insecure temp file generation

Related Vulnerabilities: CVE-2008-5141  

Dmitry E. Oboukhov discovered that flamethrower creates predictable temporary filenames, which may lead to a local denial of service through a symlink attack. For the stable distribution (etch), this problem has been fixed in version 0.1.8-1+etch1. For the unstable distribution (sid), this problem has been fixed in version 0.1.8-2. We recommend that you upgrade your flamethrower package.

Debian Security Advisory

DSA-1676-1 flamethrower -- insecure temp file generation

Date Reported:
01 Dec 2008
Affected Packages:
flamethrower
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 506350.
In Mitre's CVE dictionary: CVE-2008-5141.
More information:

Dmitry E. Oboukhov discovered that flamethrower creates predictable temporary filenames, which may lead to a local denial of service through a symlink attack.

For the stable distribution (etch), this problem has been fixed in version 0.1.8-1+etch4.

For the unstable distribution (sid), this problem has been fixed in version 0.1.8-2.

We recommend that you upgrade your flamethrower package.

Fixed in:

Debian GNU/Linux 4.0 (etch)

Source:
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch4.diff.gz
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8.orig.tar.gz
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch4.dsc
Architecture-independent component:
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch4_all.deb

MD5 checksums of the listed files are available in the original advisory.