Package name
xfig
Date
2009-09-23
Advisory ID
MDVSA-2009:244
Affected versions
CS4.0 x86_64 , CS4.0 i586

Problem description

A vulnerability was discovered and corrected in xfig:

Xfig in Debian GNU/Linux, possibly 3.2.5, allows local users to
read and write arbitrary files via a symlink attack on the (1)
xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err,
(4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7)
xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10)
xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID]
is a process ID (CVE-2009-1962).

This update provides a solution to this vulnerability.

Updated packages

CS4.0 x86_64

 148e0eab82c2090bff83cb2b2ea41ba9  corporate/4.0/x86_64/xfig-3.2.5-0.3.20060mlcs4.x86_64.rpm 
 7acec9f8cfa926f46fe656f8691e4ee0  corporate/4.0/SRPMS/xfig-3.2.5-0.3.20060mlcs4.src.rpm

CS4.0 i586

 9b524a6e53cd89941a4290a00d561e8e  corporate/4.0/i586/xfig-3.2.5-0.3.20060mlcs4.i586.rpm 
 7acec9f8cfa926f46fe656f8691e4ee0  corporate/4.0/SRPMS/xfig-3.2.5-0.3.20060mlcs4.src.rpm

References