Debian Security Advisory DSA 1003-1 (xpvm)

Summary
The remote host is missing an update to xpvm announced via advisory DSA 1003-1. Eric Romang discoverd that xpvm, a graphical console and monitor for PVM, creates a temporary file that allows local attackers to create or overwrite arbitrary files with the privileges of the user running xpvm. For the old stable distribution (woody) this problem has been fixed in version 1.2.5-7.2woody1.
Solution
For the stable distribution (sarge) this problem has been fixed in version 1.2.5-7.3sarge1. For the unstable distribution (sid) this problem has been fixed in version 1.2.5-8. We recommend that you upgrade your xpvm package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201003-1