First published: Fri Aug 05 2005(Updated: )
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | =1.5.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2353 is classified as a moderate severity vulnerability due to its local exploitability by users.
Fixing CVE-2005-2353 involves updating Thunderbird to a patched version to eliminate the symlink vulnerability.
Users of Mozilla Thunderbird version 1.5.0.9 with debugging enabled are affected by CVE-2005-2353.
The attack in CVE-2005-2353 involves a symlink attack allowing local users to create or overwrite arbitrary files.
CVE-2005-2353 cannot be exploited remotely as it requires local user access to the system.