Junglewise Threat Intelligence

CVE-1999-0114: Elm mail package symlink attack in filter command

CVE-1999-0114 · Severity: medium · CVSS 4.6 · Published 1998-01-01

Executive brief

A vulnerability in the Elm mail package, a legacy email client for Unix-like systems, allows local users to gain unauthorized access to other users' data. By exploiting a flaw in how the system handles temporary files, an attacker can read private messages or execute commands with the permissions of another user on the same machine. This could lead to a complete compromise of user privacy and local account security.

Technical details

A symlink vulnerability exists in the 'filter' command of the Elm 2.4 mail package. The application fails to securely handle temporary file creation, allowing a local attacker to create symbolic links that point to sensitive files owned by other users. When the filter utility processes mail, it may follow these links, enabling the attacker to overwrite or read files with the privileges of the user running the filter. This can result in arbitrary command execution or unauthorized data access. The vulnerability is exploited locally without requiring prior authentication beyond a standard user account.

Affected products

  • Elm Development Group Elm mail package 2.4

Timeline

  • 1998-01-01: disclosed: Initial publication date in NVD.

References

Related threats