|
SquirrelMail Change_passwd Plugin contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system as well as read the contents of /etc/shadow. The issue is due to the program creating temporary files insecurely when updating a user's password. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|