A problem with Hypermail may make local symbolic link attacks possible. It has been reported that Hypermail is vulnerable to a race condition error. Under some circumstances, Hypermail creates files in temporary directories. It may be possible to create a symbolic link in a crucial point of program execution that would result in the overwriting of files pointed to by the link. Full details of this vulnerability are not currently known. The BID will be updated as further details are disclosed.
A problem with Hypermail may make local symbolic link attacks possible. It has been reported that Hypermail is vulnerable to a race condition error. Under some circumstances, Hypermail creates files in temporary directories. It may be possible to create a symbolic link in a crucial point of program execution that would result in the overwriting of files pointed to by the link. Full details of this vulnerability are not currently known. The BID will be updated as further details are disclosed.