Bug#496005: donkey-bolonkey: Creates file in current working directory

Guillem Jover guillem at debian.org
Fri Aug 22 00:01:58 UTC 2008


Package: donkey-bolonkey
Version: 2001-5.1
Severity: important
Tags: security

Hi,

This game creates the file dkbk.hi on the current working dir every
time the game level has finished. It should probably create it under a
dot dir on the home dir (preferably following the XDG base dir spec).
Setting as important as this might be a security problem, allowing for
a symlink attack on certain conditions.

regards,
guillem





More information about the Pkg-games-devel mailing list