Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Elm_me+ | Elmme-mailer | 2.4 (including) | 2.4 (including) |