dtc 0.29.6 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/awstats.log, (b) /tmp/spam.log.#####, and (c) /tmp/spam_err.log temporary files, related to the (1) accesslog.php and (2) sa-wrapper scripts.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dtc-common | Gplhost | 0.29.6 (including) | 0.29.6 (including) |
Dtc | Ubuntu | gutsy | * |
Dtc | Ubuntu | hardy | * |
Dtc | Ubuntu | intrepid | * |
Dtc | Ubuntu | upstream | * |