The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/16207 | vdb entry patch |
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24074 | vdb entry |
http://securitytracker.com/id?1015469 | vdb entry |
http://www.osvdb.org/22320 | vdb entry |
http://secunia.com/advisories/18404 | third party advisory patch vendor advisory |