Debian Security Advisory DSA 008-1 (dialog)

Summary
The remote host is missing an update to dialog announced via advisory DSA 008-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20008-1
Insight
Matt Kraai reported that he found a problem in the way dialog creates lock-files: it did not create them safely which made it susceptible to a symlink attack. This has been fixed in version 0.9a-20000118-3bis.