sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.
Link | Tags |
---|---|
http://www.debian.org/security/2001/dsa-050 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6430 | vdb entry |
http://www.debian.org/security/2001/dsa-052 | patch vendor advisory |