Debian Security Advisory DSA 004-1 (nano)

Summary
The remote host is missing an update to nano announced via advisory DSA 004-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20004-1
Insight
The problem that was previously reported for joe also occurs with other editors. When nano (a free pico clone) unexpectedly dies it tries a warning message to a new file with a predictable name (the name of the file being edited with '.save' appended). Unfortunately that file was not created safely which made nano vulnerable to a symlink attack. This has been fixed in version 0.9.23-1 (except for powerpc, which has version 0.9.23-1.1).