First published: Tue Dec 31 2002(Updated: )
bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bogofilter | =0.9.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2267 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file in bogofilter version 0.9.0.4.
The consequences of CVE-2002-2267 include unauthorized file modifications and potential data loss due to symlink attacks.
Mitigation for CVE-2002-2267 involves upgrading to a secure version of bogofilter that does not exhibit this vulnerability, if available.
Users of bogofilter version 0.9.0.4 are affected by CVE-2002-2267, particularly those allowing local user access.
While CVE-2002-2267 is an older vulnerability, it highlights inherent risks in file handling and user permissions that are always relevant.