Debian Security Advisory
DSA-022-1 exmh -- local insecure tempfile creation
- Date Reported:
- 26 Jan 2001
- Affected Packages:
- Security database references:
- In the Bugtraq database (at SecurityFocus): BugTraq ID 2327.
In Mitre's CVE dictionary: CVE-2001-0125.
- More information:
- Former versions of the exmh program used /tmp for storing
temporary files. No checks were made to ensure that nobody placed a symlink
with the same name in /tmp in the meantime and thus was vulnerable to a symlink
attack. This could lead to a malicious local user being able to overwrite any
file writable by the user executing exmh. Upstream developers have reported and
fixed this. The exmh program now use /tmp/login unless TMPDIR or EXMHTMPDIR
We recommend you upgrade your exmh packages immediately.
- Fixed in:
Debian 2.2 (potato)
- Architecture-independent component: