CVE-2005-4536

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
libmail-audit-perl 7.04 feisty Not in release
6.10 edgy
Fixed 2.1-5sarge4
6.06 LTS dapper
Fixed 2.1-5sarge4