FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

fidogate -- write files as `news' user

Affected packages
fidogate < 4.4.9_3
fidogate-ds < 5.1.1_1


VuXML ID 3243e839-f489-11d8-9837-000c41e2cdad
Discovery 2004-08-21
Entry 2004-08-22
Modified 2004-08-23

Neils Heinen reports that the setuid `news' binaries installed as part of fidogate may be used to create files or append to file with the privileges of the `news' user by setting the LOGFILE environmental variable.