Release Date: 2008-10-13
Critical:
Moderately critical
Impact: Security Bypass
DoS
Where: From remote
Solution Status: Vendor Patch
OS: Debian GNU/Linux 4.0
Debian GNU/Linux unstable alias sid
Description:
Debian has issued an update for ruby1.8. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service).
Solution:
Apply updated packages.
Original Advisory:
DSA-1651-1:
http://www.us.debian.org/security/2008/dsa-1651
Other References:
SA31430:
http://secunia.com/advisories/31430/
SA31602:
http://secunia.com/advisories/31602/
chm2pdf Insecure Temporary Directories
Release Date: 2008-10-13
Critical:
Not critical
Impact: Privilege escalation
DoS
Where: Local system
Solution Status: Unpatched
Software: chm2pdf 0.x
Description:
A security issue has been reported in chm2pdf, which can be exploited by malicious, local users to perform certain actions with escalated privileges or to cause a DoS (Denial of Service).
The security issue is caused due to the "chm2pdf" script using temporary directories in an insecure manner. This can be exploited to stop local users from using the application or to remove arbitrary files via symlink attacks.
The security issue is reported in version 0.9.1. Other versions may also be affected.
Solution:
Restrict local access to trusted users only.
Provided and/or discovered by:
Reported by Karol Lewandowski in a Debian bug report.
Original Advisory:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501959

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic