XMail Insecure Temporary File Creation Vulnerability
BID:38427
Info
XMail Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 38427 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 25 2010 12:00AM |
| Updated: | Feb 25 2010 12:00AM |
| Credit: | The vendor. |
| Vulnerable: |
XMail XMail 1.26 |
| Not Vulnerable: |
XMail XMail 1.27 |
Discussion
XMail Insecure Temporary File Creation Vulnerability
XMail creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Versions prior to XMail 1.27 are affected.
XMail creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Versions prior to XMail 1.27 are affected.
Exploit / POC
XMail Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
XMail Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
XMail Insecure Temporary File Creation Vulnerability
References:
References:
- Feb 25, 2010 v 1.27 (XMail)
- XMail Home Page (XMail)