CVE-2004-1808Corporation Metamail vulnerability

5 documents5 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 75.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateApr 29

Description

Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jv8m-525m-hcvp: Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attac2022-04-29
CVEList
CVE-2004-1808: Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attac2005-05-10

📋Vendor Advisories

1
Red Hat
CVE-2004-1808: Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attac

💬Community

1
Bugzilla
CVE-2004-1808 metamail symlink attack2005-05-13
CVE-2004-1808 — Corporation Metamail vulnerability | cvebase