lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2010:083 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/57457 | vdb entry |
http://www.ubuntu.com/usn/USN-919-1 | vendor advisory |
http://secunia.com/advisories/39155 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2010/0734 | vdb entry vendor advisory |
https://bugs.launchpad.net/ubuntu/+bug/531569 | |
http://www.vupen.com/english/advisories/2010/0952 | vdb entry |