1.2
CVSSv2

CVE-2001-0125

Published: 12/03/2001 Updated: 10/10/2017
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

exmh 2.2 and previous versions allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

exmh exmh

debian debian linux 2.2

mandrakesoft mandrake linux 6.0

mandrakesoft mandrake linux 6.1

mandrakesoft mandrake linux 7.0

mandrakesoft mandrake linux 7.1

mandrakesoft mandrake linux 7.2

mandrakesoft mandrake linux corporate server 1.0.1

Vendor Advisories

Former versions of the exmh program used /tmp for storing temporary files No checks were made to ensure that nobody placed a symlink with the same name in /tmp in the meantime and thus was vulnerable to a symlink attack This could lead to a malicious local user being able to overwrite any file writable by the user executing exmh Upstream develop ...