Exploitation Summary
EIP tracks 1 public exploit for CVE-2001-1085. PoCs published by Charles Stevenson.
AI-analyzed exploit summary This exploit leverages a race condition in lmail's insecure temporary file handling to overwrite arbitrary files via symbolic link attacks. It brute-forces symlink creation and invokes lmail to write attacker-controlled data to the target file.
Description
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Exploits (1)
This exploit leverages a race condition in lmail's insecure temporary file handling to overwrite arbitrary files via symbolic link attacks. It brute-forces symlink creation and invokes lmail to write attacker-controlled data to the target file.