CVE
- Id
- 2190
- CVE No.
- CVE-2000-0614
- Status
- Candidate
- Description
- Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.
- Phase
- Proposed (20000719)
- Votes
- ACCEPT(1) Levy | MODIFY(1) Frech | NOOP(4) Cole, LeBlanc, Magdych, Wall | REVIEWING(1) Christey
- Comments
- Christey> This problem appears in AMaViS as well, so they may be the | same codebase. If so, then CD:SF-CODEBASE says to merge the | two (thus ADDREF BID:1461). If they are not the same | codebase, then create a separate candidate for BID:1461. | Frech> XF:linux-tnef-email-overwrite(4915) | CHANGE> [Magdych changed vote from REVIEWING to NOOP]