LWN.net Logo

sympa: symlink attack

Package(s):sympa CVE #(s):CVE-2008-4476
Created:October 9, 2009 Updated:October 14, 2009
Description: From the Mandriva advisory: sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability.
Alerts:
Mandriva MDVSA-2009:263 2009-08-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds