cve/2016/CVE-2016-6253.md

20 lines
810 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2016-6253](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6253)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
### POC
#### Reference
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- https://www.exploit-db.com/exploits/40141/
- https://www.exploit-db.com/exploits/40385/
#### Github
- https://github.com/ARPSyndicate/cvemon