2.1
CVSSv2

CVE-2002-0334

Published: 25/06/2002 Updated: 18/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

xtell (xtelld) 1.91.1 and previous versions, and 2.x prior to 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.

Vulnerable Product Search on Vulmon Subscribe to Product

xtell xtell 1.91.1

xtell xtell 2.6.1

Vendor Advisories

The xtel (an X emulator for minitel) package as distributed with Debian GNU/Linux 22 has two possible symlink attacks: xteld creates a temporary file /tmp/xtel-<user> without checking for symlinks when printing a hardcopy xtel would create a temporary file without protecting itself against symlink attacks Both problems have been ...