Former versions of the smtp-refuser package came with unchecked
logging facility to /tmp/log. This allowed deleting arbitrary,
root-owned files by any user who has write access to /tmp.
Get the Free Newsletter!
Subscribe to Developer Insider for top news, trends, & analysis