The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.
Link | Tags |
---|---|
http://www.osvdb.org/14610 | vdb entry |
http://secunia.com/advisories/14495 | third party advisory patch vendor advisory |
http://www.debian.org/security/2005/dsa-691 | patch vendor advisory |