libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.
{ "nvd_published_at": "2012-03-19T19:55:00Z", "cwe_ids": [ "CWE-59" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-11-22T20:16:20Z" }