Bug 157663 - CVE-2004-1808 metamail symlink attack
Summary: CVE-2004-1808 metamail symlink attack
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 2.1
Classification: Red Hat
Component: metamail
Version: 2.1
Hardware: All
OS: Linux
medium
low
Target Milestone: ---
Assignee: Nalin Dahyabhai
QA Contact:
URL:
Whiteboard: impact=low,public=20040512,source=deb...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-05-13 15:29 UTC by Josh Bressers
Modified: 2009-06-01 08:58 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-06-01 08:58:49 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2005-05-13 15:29:11 UTC
Extcompose in metamail does not verify the output file before writing to it,
which allows local users to overwrite arbitrary files via a symlink attack.

http://archives.neohapsis.com/archives/bugtraq/2004-03/0118.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308875

Comment 1 Mark J. Cox 2009-06-01 08:58:49 UTC
Low severity, won't fix, EOL


Note You need to log in before you can comment on or make changes to this bug.