First published: Mon Apr 05 1999(Updated: )
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
procmail |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-1999-0475 is generally considered to be medium due to the potential for local users to read sensitive files.
To fix CVE-1999-0475, ensure that appropriate file permissions are set on .procmailrc files and consider updating to the latest version of procmail.
CVE-1999-0475 affects local users running procmail who can access the .procmailrc file.
CVE-1999-0475 is classified as a race condition vulnerability.
An attacker can exploit CVE-1999-0475 to read arbitrary files that are accessible to the user executing procmail.