YaMT contains a flaw that allows an attacker to overwrite arbitrary files. The issue is due to the sort and rename options not properly sanitizing user input, renaming filenames to be set with characters that are interpreted by the shell such as "/../../filename".
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
Solution
Upgrade to version yamt-0.5-1277 or higher, as it has been reported to fix this vulnerability. In addition, Suse has released a patch for some older versions.