tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.
2002-10-28T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tkmail | tkmail | 4.0_beta1 | Yes |
Application | tkmail | tkmail | 4.0_beta4 | Yes |
Application | tkmail | tkmail | 4.0_beta6 | Yes |
Application | tkmail | tkmail | 4.0_beta8 | Yes |
Application | tkmail | tkmail | 4.0_beta9 | Yes |