The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.
{
"binaries": [
{
"binary_name": "browser-plugin-gnash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-common",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-common-opengl",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-cygnal",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-dbg",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-dev",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-doc",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-ext-fileio",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-ext-lirc",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-ext-mysql",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-opengl",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "gnash-tools",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "klash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "klash-opengl",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "konqueror-plugin-gnash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "mozilla-plugin-gnash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "python-gtk-gnash",
"binary_version": "0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "swfdec-gnome",
"binary_version": "1:0.8.11~git20130903-3ubuntu1"
},
{
"binary_name": "swfdec-mozilla",
"binary_version": "0.8.11~git20130903-3ubuntu1"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "browser-plugin-gnash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "browser-plugin-gnash-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-common",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-common-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-common-opengl",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-cygnal",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-cygnal-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-dbg",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-dev",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-dev-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-doc",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-fileio",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-fileio-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-lirc",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-lirc-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-mysql",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-ext-mysql-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-opengl",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-tools",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "gnash-tools-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "klash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "klash-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "klash-opengl",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "konqueror-plugin-gnash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "konqueror-plugin-gnash-dbgsym",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "mozilla-plugin-gnash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "python-gtk-gnash",
"binary_version": "0.8.11~git20160109-1build1"
},
{
"binary_name": "swfdec-gnome",
"binary_version": "1:0.8.11~git20160109-1build1"
},
{
"binary_name": "swfdec-mozilla",
"binary_version": "0.8.11~git20160109-1build1"
}
],
"availability": "No subscription required"
}