Lmail Temporary File Race Condition Vulnerability
BID:2984
Info
Lmail Temporary File Race Condition Vulnerability
| Bugtraq ID: | 2984 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 05 2001 12:00AM |
| Credit: | Reported by Charles Stevenson <[email protected]> on July 5, 2001. |
| Vulnerable: |
Jon Zeeff lmail 2.7 |
| Not Vulnerable: | |
Discussion
Lmail Temporary File Race Condition Vulnerability
Jon Zeeff's lmail is a local mail delivery agent (LDA) designed to provide mail-to-pipe and mail-to-file aliasing for smail.
A race condition vulnerability exists in lmail. The lmail program makes insecure use of temporary files, making it susceptible to symbolic link attacks. The program also writes data from the standard input stream (stdin) directly to the temporary file.
Because lmail is usually installed setuid root, it may be possible for a local user to overwrite any file on a system with arbitrary data.
Jon Zeeff's lmail is a local mail delivery agent (LDA) designed to provide mail-to-pipe and mail-to-file aliasing for smail.
A race condition vulnerability exists in lmail. The lmail program makes insecure use of temporary files, making it susceptible to symbolic link attacks. The program also writes data from the standard input stream (stdin) directly to the temporary file.
Because lmail is usually installed setuid root, it may be possible for a local user to overwrite any file on a system with arbitrary data.
Exploit / POC
References
Lmail Temporary File Race Condition Vulnerability
References:
References: