CVE-2007-6208
published 2007-12-04CVE-2007-6208: sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary…
PriorityP49low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.36%
28.7th percentile
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| claws-mail | claws-mail | >= 0 < 3.1.0-2 | 3.1.0-2 |
| claws-mail | claws-mail | >= 0 < 3.1.0-2 | 3.1.0-2 |
| claws-mail | claws-mail | >= 0 < 3.1.0-2 | 3.1.0-2 |
| claws-mail | claws-mail | >= 0 < 3.1.0-2 | 3.1.0-2 |
| debian | claws-mail | < claws-mail 3.1.0-2 (bookworm) | claws-mail 3.1.0-2 (bookworm) |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wf73-pxpq-869j: sylprint
ghsa_unreviewed·2022-05-01
CVE-2007-6208 [LOW] CWE-59 GHSA-wf73-pxpq-869j: sylprint
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
OSV
CVE-2007-6208: sylprint
osv·2007-12-04·CVSS 3.6
CVE-2007-6208 [LOW] CVE-2007-6208: sylprint
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
Debian
CVE-2007-6208: claws-mail - sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwri...
vendor_debian·2007·CVSS 3.6
CVE-2007-6208 [LOW] CVE-2007-6208: claws-mail - sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwri...
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
Scope: local
bookworm: resolved (fixed in 3.1.0-2)
bullseye: resolved (fixed in 3.1.0-2)
forky: resolved (fixed in 3.1.0-2)
sid: resolved (fixed in 3.1.0-2)
trixie: resolved (fixed in 3.1.0-2)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454089http://osvdb.org/42478http://secunia.com/advisories/27897http://secunia.com/advisories/28402http://security.gentoo.org/glsa/glsa-200801-03.xmlhttp://www.securityfocus.com/bid/26676http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454089http://osvdb.org/42478http://secunia.com/advisories/27897http://secunia.com/advisories/28402http://security.gentoo.org/glsa/glsa-200801-03.xmlhttp://www.securityfocus.com/bid/26676
2007-12-04
Published