Getmail Local Symbolic Link Vulnerability

BID:11224

Info

Getmail Local Symbolic Link Vulnerability

Bugtraq ID: 11224
Class: Race Condition Error
CVE: CVE-2004-0880
CVE-2004-0881
Remote: No
Local: Yes
Published: Sep 20 2004 12:00AM
Updated: Jul 12 2009 07:06AM
Credit: The discovery of this issue is credited to David Watson.
Vulnerable: Slackware Linux 10.0
Slackware Linux 9.1
Slackware Linux -current
getmail getmail 4.1.5
getmail getmail 4.1.4
getmail getmail 4.1.3
getmail getmail 4.1.2
getmail getmail 4.1.1
getmail getmail 4.1
getmail getmail 4.0.13
getmail getmail 4.0.12
getmail getmail 4.0.11
getmail getmail 4.0.10
getmail getmail 4.0.9
getmail getmail 4.0.8
getmail getmail 4.0.7
getmail getmail 4.0.6
getmail getmail 4.0.5
getmail getmail 4.0.4
getmail getmail 4.0.3
getmail getmail 4.0.2
getmail getmail 4.0.1
getmail getmail 4.0 .0b10
getmail getmail 4.0
getmail getmail 2.3.7
getmail getmail 3.x
Gentoo Linux 1.4
Not Vulnerable: getmail getmail 4.2
getmail getmail 3.2.5

Discussion

Getmail Local Symbolic Link Vulnerability

Reportedly getmail is affected by a local symbolic link vulnerability. This issue is due to a failure of the application to validate files prior to writing to them.

An attacker may leverage this issue to cause arbitrary files to be written to with the privileges of a user that sends messages to an attacker-controlled file. This may facilitate privilege escalation or destruction of data.

Exploit / POC

Getmail Local Symbolic Link Vulnerability

No exploit is required to leverage this issue.

Solution / Fix

Getmail Local Symbolic Link Vulnerability

Solution:
The vendor has released an upgrade dealing with this issue.

Gentoo Linux has released advisory GLSA 200409-32 addressing this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=net-mail/getmail-4.2.0"
emerge ">=net-mail/getmail-4.2.0"

Debian has released an advisory (DSA 553-1) and fixes to address this issue. See the referenced advisory for fix information.

Slackware Linux has released advisory SSA:2004-278-01 along with fixes to address this issue. Please see the referenced advisory for further information.


Slackware Linux -current

Slackware Linux 10.0

getmail getmail 2.3.7

getmail getmail 4.0

getmail getmail 4.0 .0b10

getmail getmail 4.0.1

getmail getmail 4.0.10

getmail getmail 4.0.11

getmail getmail 4.0.12

getmail getmail 4.0.13

getmail getmail 4.0.2

getmail getmail 4.0.3

getmail getmail 4.0.4

getmail getmail 4.0.5

getmail getmail 4.0.6

getmail getmail 4.0.7

getmail getmail 4.0.8

getmail getmail 4.0.9

getmail getmail 4.1

getmail getmail 4.1.1

getmail getmail 4.1.2

getmail getmail 4.1.3

getmail getmail 4.1.4

getmail getmail 4.1.5

Slackware Linux 9.1

References

Getmail Local Symbolic Link Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report