Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Nautilus |
Eazel |
1.0.4 (including) |
1.0.4 (including) |
Red Hat Linux 7.2 |
RedHat |
|
* |
References