xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.
Software | From | Fixed in |
---|---|---|
xine / xine | 0.9.13 | 0.9.13.x |
xine / xine | 1_beta1 | 1_beta1.x |
xine / xine | 1_beta10 | 1_beta10.x |
xine / xine | 1_beta11 | 1_beta11.x |
xine / xine | 1_beta12 | 1_beta12.x |
xine / xine | 1_beta2 | 1_beta2.x |
xine / xine | 1_beta3 | 1_beta3.x |
xine / xine | 1_beta4 | 1_beta4.x |
xine / xine | 1_beta5 | 1_beta5.x |
xine / xine | 1_beta6 | 1_beta6.x |
xine / xine | 1_beta7 | 1_beta7.x |
xine / xine | 1_beta8 | 1_beta8.x |
xine / xine | 1_beta9 | 1_beta9.x |
xine / xine | 1_rc0a | 1_rc0a.x |
xine / xine | 1_rc1 | 1_rc1.x |
xine / xine | 1_rc2 | 1_rc2.x |
xine / xine | 1_rc3 | 1_rc3.x |
xine / xine | 1_rc3a | 1_rc3a.x |
xine / xine | 1_rc3b | 1_rc3b.x |