mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
810 B
810 B
CVE-2016-6253
Description
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
POC
Reference
- http://packetstormsecurity.com/files/138021/NetBSD-mail.local-8-Local-Root.html
- https://www.exploit-db.com/exploits/40141/
- https://www.exploit-db.com/exploits/40385/