DSA-1764 tunapie -- several vulnerabilitiesID: oval:org.mitre.oval:def:8185 | Date: (C)2009-12-15 (M)2021-06-02 |
Class: PATCH | Family: unix |
Several vulnerabilities have been discovered in Tunapie, a GUI frontend to video and radio streams. The Common Vulnerabilities and Exposures project identifies the following problems: Kees Cook discovered that insecure handling of temporary files may lead to local denial of service through symlink attacks. Mike Coleman discovered that insufficient escaping of stream URLs may lead to the execution of arbitrary commands if a user is tricked into opening a malformed stream URL.