mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bacula | Bacula | 2.4.2 (including) | 2.4.2 (including) |
Bacula | Ubuntu | dapper | * |
Bacula | Ubuntu | gutsy | * |
Bacula | Ubuntu | hardy | * |
Bacula | Ubuntu | upstream | * |