Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=112958392512513&w=2 | mailing list |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334350 | exploit |
http://www.zataz.net/adviso/flexbackup-09192005.txt | exploit vendor advisory |
http://www.debian.org/security/2006/dsa-1216 | vendor advisory |
http://secunia.com/advisories/17209 | exploit third party advisory vendor advisory |
http://secunia.com/advisories/23008 | third party advisory |
http://securitytracker.com/id?1015068 | vdb entry exploit |