aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.
Link | Tags |
---|---|
http://shellcode.org/pipermail/debian-audit/2004-December/000078.html | mailing list |
http://secunia.com/advisories/13679 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/12128 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18698 | vdb entry |
http://www.osvdb.org/12632 | vdb entry |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287604 |