tags 496422 confirmed security
thanks

Hi,

The issue is indeed clearly present in asciiview, for example:

    myconvert $name >/tmp/aview$$.pgm

Since it's a shell script this can probably be quite easily addressed by using 
the essential 'mktemp' to create the temporary file.


cheers,
Thijs

Attachment: pgpygPo7mKxX4.pgp
Description: PGP signature

Reply via email to