3.6
CVSSv2

CVE-2007-6208

Published: 04/12/2007 Updated: 15/11/2008
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

claws mail claws mail tools

Vendor Advisories

Debian Bug report logs - #454089 CVE-2007-6208 insecure tmp file handling in sylprintpl prone to symlink attack Package: claws-mail-tools; Maintainer for claws-mail-tools is Ricardo Mones <mones@debianorg>; Source for claws-mail-tools is src:claws-mail (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> ...