The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these characters in strings received from the network, which might allow remote attackers to conduct absolute path traversal attacks and overwrite arbitrary files via a ~ in a pathname that is used for a file transfer in an Internet game, a different vulnerability than CVE-2011-1932.
1. ffmpeg/libav out of array write in AMV parsing
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=624339 http://seclists.org/bugtraq/2011/Apr/257 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=89f903b3d5ec38c9c5d90fba7e626fa0eda61a32 Use CVE-2011-1931 2. widelands directory traversal
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617960 http://bazaar.launchpad.net/~widelands-dev/widelands/build-15/revision/5021 Use CVE-2011-1932 3. SQL injection in Jifty::DBI
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622919 http://lists.jifty.org/pipermail/jifty-devel/2011-April/002426.html Use CVE-2011-1933 4. lilo: lilo-uuid-diskid makes lilo.conf world-readable
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615103 Use CVE-2011-1934 5. libpcap packet truncation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=623868 http://thread.gmane.org/gmane.network.tcpdump.devel/5018 Use CVE-2011-1935
Thanks.
-- JB