FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

fidogate -- write files as `news' user

Affected packages
fidogate < 4.4.9_3
fidogate-ds < 5.1.1_1

Details

VuXML ID 3243e839-f489-11d8-9837-000c41e2cdad
Discovery 2004-08-21
Entry 2004-08-22
Modified 2004-08-23

Neils Heinen reports that the setuid `news' binaries installed as part of fidogate may be used to create files or append to file with the privileges of the `news' user by setting the LOGFILE environmental variable.

References

URL http://cvs.sourceforge.net/viewcvs.py/fidogate/fidogate/ChangeLog?rev=4.320&view=markup