Frank Lichtenheld and Nico Golde discovered that WML, an off-line HTML generation toolkit, creates insecure temporary files in the eperl and ipp backends and in the wmg.cgi script, which could lead to a local denial of service by overwriting files.
The old stable distribution (sarge) is not affected.
For the stable distribution (etch), these problems have been fixed in version 2.0.11-1etch1.
We recommend that you upgrade your wml packages.
MD5 checksums of the listed files are available in the original advisory.
MD5 checksums of the listed files are available in the revised advisory.