Title: OpenDKIM unsafe /tmp usage. Author: Michael Orlitzky.
Title: OpenDKIM unsafe /tmp usage. Author: Michael Orlitzky.
Summary
The OpenDKIM test suite relied on a fixed path under the world-writable /tmp directory for its temporary keys. An attacker could exploit the situation to overwrite files belonging to the user who runs the test suite.
About the research
CVE identifiers provide a standard public reference for known cybersecurity vulnerabilities. The disclosure was published so affected users and maintainers could identify the issue and apply the appropriate correction.