tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "pktstat", "binary_version": "1.8.5-3" } ], "ubuntu_priority": "medium" }