[SECURITY] [DSA 1764-1] New tunapie packages fix several vulnerabilities

Debian Security Advisory DSA-1764-1                  security@xxxxxxxxxx
http://www.debian.org/security/                       Moritz Muehlenhoff
April 07, 2009                        http://www.debian.org/security/faq
Package        : tunapie
Vulnerability  : several
Problem type   : local(remote)
Debian-specific: no
CVE Id(s)      : CVE-2009-1253 CVE-2009-1254

Several vulnerabilities have been discovered in Tunapie, a GUI frontend
to video and radio streams. The Common Vulnerabilities and Exposures
project identifies the following problems:


    Kees Cook discovered that insecure handling of temporary files may
    lead to local denial of service through symlink attacks.


    Mike Coleman discovered that insufficient escaping of stream
    URLs may lead to the execution of arbitrary commands if a user
    is tricked into opening a malformed stream URL.

For the old stable distribution (etch), these problems have been fixed
in version 1.3.1-1+etch2. Due to a technical problem, this update cannot
be released synchronously with the stable (lenny) version, but will
appear soon.

For the stable distribution (lenny), these problems have been fixed in
version 2.1.8-2.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your tunapie package.

Debian GNU/Linux 5.0 alias lenny
Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

    Size/MD5 checksum:      986 65d527cb9fc306fa3fb84f9e46533e40
    Size/MD5 checksum:    49859 74228ac48e1633749fe3774d225917d9
    Size/MD5 checksum:     5878 cb5766c089606fb839b327483a2a27ca

Architecture independent packages:

    Size/MD5 checksum:    46692 d3e0539b43b439f944ca68294937ed9c

