PT-2008-6295 · Unknown+1 · Maildirsync+1
Published
2008-11-18
·
Updated
2017-08-08
·
CVE-2008-5150
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
maildirsync version 1.1
Description
The issue allows local users to append data to arbitrary files via a symlink attack on a temporary file.
Recommendations
For maildirsync version 1.1, consider restricting access to the sample.sh script until a patch is available. As a temporary workaround, avoid using the sample.sh script in maildirsync to minimize the risk of exploitation.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Maildirsync