Debian Security Advisory DSA 656-1 security@debian.org
http://www.debian.org/security/ Martin Schulze
January 25th, 2005 http://www.debian.org/security/faq

Package : vdr
Vulnerability : insecure file access
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2005-0071

Javier Fernández-Sanguino Peña from the Debian Security Audit Team has discovered that the vdr daemon which is used for video disk recorders for DVB cards can overwrite arbitrary files.

For the stable distribution (woody) this problem has been fixed in version 1.0.0-1woody2.

For the unstable distribution (sid) this problem has been fixed in version 1.2.6-6.

We recommend that you upgrade your vdr package.

Debian GNU/Linux 3.0 alias woody

These files will probably be moved into the stable distribution on its next update.

