Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/1677 | vdb entry |
http://marc.info/?l=bugtraq&m=87773365324657&w=2 | mailing list |