jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Jmcce |
Jmcce |
1.3.8 (including) |
1.3.8 (including) |
References