Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Esearch eupdatedb Symbolic Link Vulnerability

It has been reported that eupdatedb, an esearch utility is affected by a symbolic link vulnerability. This issue is due to a failure of the application to properly handle temporary file creation.

An attacker can leverage this vulnerability to create an arbitrary file with the permissions of an unsuspecting user that has activated the vulnerable utility; facilitating a number of possible attacks.







 

Privacy Statement
Copyright 2008, SecurityFocus