Candidate: CVE-2012-0808 PublicDate: 2012-03-19 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0808 Description: as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655496 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_as31: upstream_as31: released (2.3.1-5) hardy_as31: DNE lucid_as31: ignored (reached end-of-life) maverick_as31: ignored (reached end-of-life) natty_as31: ignored (reached end-of-life) oneiric_as31: ignored (reached end-of-life) precise_as31: ignored (reached end-of-life) precise/esm_as31: DNE (precise was needed) quantal_as31: not-affected (2.3.1-6) raring_as31: not-affected (2.3.1-6) saucy_as31: not-affected (2.3.1-6) trusty_as31: not-affected (2.3.1-6) trusty/esm_as31: DNE (trusty was not-affected [2.3.1-6]) utopic_as31: not-affected (2.3.1-6) vivid_as31: not-affected (2.3.1-6) vivid/stable-phone-overlay_as31: DNE vivid/ubuntu-core_as31: DNE wily_as31: not-affected (2.3.1-6) xenial_as31: not-affected (2.3.1-6) yakkety_as31: not-affected (2.3.1-6) zesty_as31: not-affected (2.3.1-6) devel_as31: not-affected (2.3.1-6)