First published: Tue Dec 04 2007(Updated: )
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claws-Mail |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6208 has a moderate severity level due to its potential for local privilege escalation through symlink attacks.
To fix CVE-2007-6208, ensure that the temporary files created by sylprint.pl are not vulnerable to symlink attacks by implementing proper file path sanitization.
CVE-2007-6208 affects the claws-mail-tools package in Claws Mail.
Local users of Claws Mail who have access to the system are impacted by CVE-2007-6208.
CVE-2007-6208 facilitates symlink attacks that allow local users to overwrite arbitrary files.