CVE-2020-35766

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of self-test programs are included here for unit-testing the library" situation.
References
Link Resource
https://github.com/trusteddomainproject/OpenDKIM/issues/113 Exploit Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:opendkim:opendkim:*:*:*:*:*:*:*:*

Information

Published : 2020-12-28 12:15

Updated : 2020-12-30 08:38


NVD link : CVE-2020-35766

Mitre link : CVE-2020-35766


JSON object : View

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

Advertisement

dedicated server usa

Products Affected

opendkim

  • opendkim