Debian Information for VU#487102

Multiple tools within the Netpbm package create temporary files in an insecure manner



Vendor Statement

Debian Security Advisory DSA 426-1                                        Matt Zimmerman
January 18th, 2004            
Package        : netpbm-free
Vulnerability  : insecure temporary files
Problem-Type   : local
Debian-specific: no
CVE Ids        : CAN-2003-0924

netpbm is graphics conversion toolkit made up of a large number of
single-purpose programs.  Many of these programs were found to create
temporary files in an insecure manner, which could allow a local
attacker to overwrite files with the privileges of the user invoking a
vulnerable netpbm tool.

For the current stable distribution (woody) these problems have been
fixed in version 2:9.20-8.4.

For the unstable distribution (sid) these problems have been fixed in
version 2:9.25-9.

We recommend that you update your netpbm-free package.

Upgrade Instructions
wget url
       will fetch the file for you
dpkg -i file.deb
       will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
       will update the internal database
apt-get upgrade
       will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



