| PROBLEM: | There are several local vulnerabilities in xwine, a graphical user interface for the WINE emulator. |
| PLATFORM: | Debian GNU/Linux 4.0 (etch) |
| DAMAGE: | Could allow local user to change local files and or execute arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. Could allow the removal of arbitrary files belonging to users who invoke the program and edit it such that arbitrary commands could be executed whenever any local user executed a program under WINE. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
2.1 1.7 (AV:L/AC:L/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-239.shtml |
| ORIGINAL BULLETIN: | http://www.debian.org/security/2008/dsa-1526 |
| CVE: | CVE-2008-0930 CVE-2008-0931 |
[***** Start Debian Security Advisory DSA-1526-1 *****]
Steve Kemp from the Debian Security Audit project discovered several local vulnerabilities in xwine, a graphical user interface for the WINE emulator.
The Common Vulnerabilities and Exposures project identifies the following problems:
The xwine command makes unsafe use of local temporary files when printing. This could allow the removal of arbitary files belonging to users who invoke the program.
The xwine command changes the permissions of the global WINE configuration file such that it is world-writable. This could allow local users to edit it such that arbitrary commands could be executed whenever any local user executed a program under WINE.
For the stable distribution (etch), these problems have been fixed in version 1.0.1-1etch1.
We recommend that you upgrade your xwine package.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1526-1 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org