Debian: 'nextaw', 'xaw3d', and 'xaw95' vulnerabilities
Debian It has been reported that the AsciiSrc and MultiSrc widget in the Athena widget library handle temporary files insecurely.

Debian Security Advisory DSA-037-1                                            Martin Schulze
March 7, 2001

Package        : nextaw, xaw3d, xaw95
Vulnerability  : insecure tempfile handling
Type           : local insecure tempfile bug
Debian-specific: no
Fixed version  : nextaw 0.5.1-34potato1
                 xaw3d 1.3-6.9potato1
                 xaw95 1.1-4.6potato1

It has been reported that the AsciiSrc and MultiSrc widget in the
Athena widget library handle temporary files insecurely.  Joey Hess
has ported the bugfix from XFree86 to these Xaw replacements

We recommend you upgrade your nextaw, xaw3d and xaw95 packages.

Debian GNU/Linux 2.2 alias potato

  Potato was released for the alpha, arm, i386, m68k, powerpc and sparc
  architectures.  This package, though, is only fixed for i386 and
  m68k.  The version for sparc is still vulnerable and isn't
  maintained anymore.

