The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Abuse-sdl |
Abuse |
* |
2.0 (including) |
References