UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlin…
Info
Summary
UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://marc.info/?l=bugtraq&m=87602167419835&w=2
- http://marc.info/?l=bugtraq&m=87602167419839&w=2
- http://marc.info/?l=bugtraq&m=87602167420726&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/431
- http://marc.info/?l=bugtraq&m=87602167419835&w=2
- http://marc.info/?l=bugtraq&m=87602167419839&w=2
- http://marc.info/?l=bugtraq&m=87602167420726&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/431
Timeline
- nvd_ingest NVD