tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.
Link | Tags |
---|---|
http://www.debian.org/security/2002/dsa-172 | patch vendor advisory |
http://www.securityfocus.com/bid/5911 | vdb entry |
http://www.iss.net/security_center/static/10307.php | vdb entry vendor advisory |