Matt Welsh sgmltool Symlink Vulnerability...

- AV AC AU C I A
发布: 2001-05-04
修订: 2025-04-13

sgmltool is a suite of programs used in processing and coverting SGML files to other formats. An sgmltool component makes insecure use of temporary files. If an attacker can determine the name of the temporary file prior to its creation, a symbolic link could be created pointing to a target file for which the sgmltool process owner has write permissions. In this event, sgmltool will overwrite the contents of the target file with its own output.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息