tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
{ "binaries": [ { "binary_version": "1.8.5-3", "binary_name": "pktstat" } ], "availability": "No subscription required" }