UBUNTU-CVE-2017-5899
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-5899
UBUNTU-CVE-2017-5899
Summary:
Details: Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
References: https://ubuntu.com/security/CVE-2017-5899, https://www.mail-archive.com/[email protected]/msg00551.html, https://git.sdaoden.eu/cgit/s-nail.git/commit/?id=f797c27efecad45af191c518b7f87fda32ada160, https://git.sdaoden.eu/cgit/s-nail.git/commit/?id=f2699449b66dd702a98925bd1b11153a6f7294bf, https://www.openwall.com/lists/oss-security/2017/01/27/7, https://www.cve.org/CVERecord?id=CVE-2017-5899, https://ubuntu.com/security/notices/USN-4820-1
Affected packages
Package
Name: s-nail
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
