Skip to content

CVE-2013-0350: Drop tcp_smtp log#7

Open
bgermann wants to merge 1 commit intodleonard0:masterfrom
bgermann:cve-2013-0350
Open

CVE-2013-0350: Drop tcp_smtp log#7
bgermann wants to merge 1 commit intodleonard0:masterfrom
bgermann:cve-2013-0350

Conversation

@bgermann
Copy link

tmp_smtp.c allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

This is adapted from the patch by Jari Aalto that Debian has included for this.

tmp_smtp.c allows local users to overwrite arbitrary files via a symlink
attack on /tmp/smtp.log.

This is adapted from the patch by Jari Aalto that Debian has included for this.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant