Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.
Link | Tags |
---|---|
http://www.horde.org/imp/2.2/news.php | patch |
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-025.0.txt | vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2001-05/0303.html | mailing list patch vendor advisory |