Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Marco Van Berkum

#23835de 53,635
9.9CVSS total
Vulnerabilidades · 2
Baixa
1
Alta
1
PT-2004-1437
2.1
2004-03-18
Mailmgr · Mailmgr · CVE-2004-0283
**Name of the Vulnerable Software and Affected Versions** Mailmgr version 1.2.3 **Description** The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files /tmp/mailmgr.unsort, /tmp/mailmgr.tmp, or /tmp/mailmgr.sort. **Recommendations** For Mailmgr version 1.2.3, consider restricting access to the temporary files /tmp/mailmgr.unsort, /tmp/mailmgr.tmp, and /tmp/mailmgr.sort to prevent a symlink attack until a patch is available.
PT-2003-2312
7.8
2003-12-31
Majordomo · Majordomo · CVE-2003-1367
**Name of the Vulnerable Software and Affected Versions** Majordomo versions 1.94.4 and earlier **Description** The issue allows remote attackers to identify the email addresses of members of mailing lists via a "which" command, due to the `which access` variable being set to "open" by default. **Recommendations** For Majordomo versions 1.94.4 and earlier, consider changing the `which access` variable from "open" to a more restrictive setting to prevent remote attackers from identifying email addresses of mailing list members.