Package: winetricks
Version: 0.0+20141009+svn1208-2
Severity: important

Dear Maintainer,

 the winetricks script has insecure handling of /tmp filenames in a lot
of places.  It doesn't create the files in a save way.  Please consider
using mktemp from the coreutils package to create those files in a
secure way that doesn't allow for symlink attacks and similar.  This is
not limited to hardcoded /tmp/early_wine.err.txt file but also to all
the filenames that only contain the process ID in the filenames too.
Technicly all files that are created in /tmp/ are done insecure here.

 Thanks,
Rhonda

-- System Information:
Debian Release: 7.8
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=de_AT.UTF-8, LC_CTYPE=de_AT.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to