|
KDE Kmail contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when Kmail creates unsafe temporary files to save attachments in the "/tmp" directory, which will allow a local attacker to create or overwrite files with contents they can select in any directory and/or file writable by the user running KMail. By compromising the UID of another Kmail user, a local attacker can escalate their privileges.
|