Описание
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-6253
- https://www.exploit-db.com/exploits/40141
- https://www.exploit-db.com/exploits/40385
- http://akat1.pl/?id=2
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2016-006.txt.asc
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- http://www.rapid7.com/db/modules/exploit/unix/local/netbsd_mail_local
- http://www.securityfocus.com/bid/92101
- http://www.securitytracker.com/id/1036429
Связанные уязвимости
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
Уязвимость операционной системы NetBSD, позволяющая нарушителю обойти защиту от межсайтовой подмены запросов