popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7707 | vdb entry |
http://www.securityfocus.com/archive/1/246069 | mailing list |