Bug#675744: openssn: Creates files under data/ on current working dir

Guillem Jover guillem at debian.org
Sun Jun 3 04:20:10 UTC 2012


Package: openssn
Version: 1.1-1
Severity: important

Hi!

This program creates two files under `pwd`/data/ if that directory
exists on the current working dir, namely font.dat and largefont.dat.
This is a security issue as the creation also follows symlinks.

thanks,
guillem





More information about the Pkg-games-devel mailing list