3.7
CVSSv2

CVE-2001-1085

Published: 05/07/2001 Updated: 10/10/2017
CVSS v2 Base Score: 3.7 | Impact Score: 6.4 | Exploitability Score: 1.9
VMScore: 375
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Lmail 2.7 and previous versions allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

jon zeeff lmail 2.7

Exploits

source: wwwsecurityfocuscom/bid/2984/info Jon Zeeff's lmail is a local mail delivery agent (LDA) designed to provide mail-to-pipe and mail-to-file aliasing for smail A race condition vulnerability exists in lmail The lmail program makes insecure use of temporary files, making it susceptible to symbolic link attacks The program also wr ...