[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1526 xwine -- several vulnerabilities

ID: oval:org.mitre.oval:def:7999Date: (C)2009-12-15   (M)2021-09-11
Class: PATCHFamily: unix




Steve Kemp from the Debian Security Audit project discovered several local vulnerabilities in xwine, a graphical user interface for the WINE emulator. The Common Vulnerabilities and Exposures project identifies the following problems: The xwine command makes unsafe use of local temporary files when printing. This could allow the removal of arbitrary files belonging to users who invoke the program. The xwine command changes the permissions of the global WINE configuration file such that it is world-writable. This could allow local users to edit it such that arbitrary commands could be executed whenever any local user executed a program under WINE.

Platform:
Debian 4.0
Product:
xwine
Reference:
DSA-1526
CVE-2008-0930
CVE-2008-0931
CVE    2
CVE-2008-0930
CVE-2008-0931
CPE    1
cpe:/o:debian:debian_linux:4.x

© SecPod Technologies