xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=107997911025558&w=2 | mailing list |
http://www.debian.org/security/2004/dsa-477 | patch vendor advisory |
http://www.securityfocus.com/bid/9939 | vdb entry vendor advisory |
http://security.gentoo.org/glsa/glsa-200404-20.xml | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15564 | vdb entry |