emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.
Software | From | Fixed in |
---|---|---|
emesene / emesene | 1.0 | 1.0.x |
emesene / emesene | - | 1.6.1.x |
emesene / emesene | 1.5 | 1.5.x |
emesene / emesene | 1.5.1 | 1.5.1.x |
emesene / emesene | 1.0.1 | 1.0.1.x |
emesene / emesene | 1.6 | 1.6.x |