Required CVE Record Information
Description
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
References 7 Total
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496359
- openwall.com: [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire mailing-list
- https://bugs.gentoo.org/show_bug.cgi?id=235770
- securityfocus.com: 30877 vdb-entry
- secunia.com: 31648 third-party-advisory
- http://dev.gentoo.org/~rbu/security/debiantemp/citadel-server
- exchange.xforce.ibmcloud.com: citadel-migratealiases-symlink(44734) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496359 x_transferred
- openwall.com: [oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire mailing-listx_transferred
- https://bugs.gentoo.org/show_bug.cgi?id=235770 x_transferred
- securityfocus.com: 30877 vdb-entryx_transferred
- secunia.com: 31648 third-party-advisoryx_transferred
- http://dev.gentoo.org/~rbu/security/debiantemp/citadel-server x_transferred
- exchange.xforce.ibmcloud.com: citadel-migratealiases-symlink(44734) vdb-entryx_transferred