|
|
| |
|
| |
sympa: symlink attack
| Package(s): | sympa |
CVE #(s): | CVE-2008-4476
|
| Created: | October 9, 2009 |
Updated: | October 14, 2009 |
| Description: |
From the Mandriva advisory:
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary
files via a symlink attack on a temporary file. NOTE: wwsympa.fcgi
was also reported, but the issue occurred in a dead function, so it
is not a vulnerability. |
| Alerts: |
|
( Log in to post comments)
|
|
|