LWN.net Logo

mime-support: insecure temporary file creation

Package(s):mime-support CVE #(s):
Created:April 22, 2003 Updated:April 30, 2003
Description: Colin Phipps discovered several problems in mime-support, that contains support programs for the MIME control files 'mime.types' and 'mailcap'. When a temporary file is to be used it is created insecurely, allowing an attacker to overwrite arbitrary under the user id of the person executing run-mailcap, most probably root. Additionally the program did not properly escape shell escape characters when executing a command. This is unlikely to be exploitable, though.
Alerts:
Debian DSA-292-3 2003-04-30
Debian DSA-292-2 2003-04-23
Debian DSA-292-1 2003-04-22

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds