|
IBM AIX Mail contains a flaw that is triggered when a .forward file is created with a pipe character and path to an arbitrary file (e.g. |/some/arbitrary/file/you/want/to/overwrite). By sending an email to the user with such a forward file, the arbitrary file will be overwritten. This can be used to escalate privileges.
|