Josh Triplett
2008-Oct-28 01:52 UTC
[Secure-testing-team] Bug#503750: Save directory defaults to /tmp/balazar3_v0.1_saves
Package: balazar3 Version: 0.1-1 Severity: grave Tags: security Justification: user security hole balazar3 uses /tmp/balazar3_v0.1_saves as its default save game directory. This introduces an insecure temporary file vulnerability. The default save directory should live inside $HOME. - Josh Triplett -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, ''unstable''), (1, ''experimental'') Architecture: amd64 (x86_64) Kernel: Linux 2.6.27-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages balazar3 depends on: ii balazar3-3d 0.1-1 dungeon adventure game with multip balazar3 recommends no packages. balazar3 suggests no packages. -- no debconf information