Vulnerabilities > CVE-2003-1324 - Local Security vulnerability in Elmme-Mailer ELM Me+ 2.4

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
elmme-mailer

Summary

Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.

Vulnerable Configurations

Part Description Count
Application
Elmme-Mailer
1