CVE-2017-5899
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
- S-nail Project S-nail
- ≤ 14.8.5
- Fix
- Available
- CVSS 3.0
- 7.0 HIGH
- EPSS
- 1.0% (61th percentile)
- Weakness
- CWE-22, CWE-362
- NVD status
- Modified
- Published
- 2017-03-27
CVE-2017-5899 at NVD
4 known exploits for CVE-2017-5899
Proof-of-concept code and exploit modules indexed by Sploitus