CVE-1999-1263
Executive Summary
Metamail versions prior to 2.7-7.2 allow remote attackers to overwrite arbitrary files by sending an e‑mail with a uuencoded attachment that includes a full pathname. The uuencode script (e.g., sun-audio-file) processes the attachment and writes to the specified path, enabling arbitrary file modification without authentication.
Authoritative CVE Metadata - CVSS Base Score: 2.6 (LOW) - Published: 2003-08-15T04:00:00.000 - Last Modified: 2026-09-25T20:10:00.123
Original Description: Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
"They must often change, who would be constant in happiness or wisdom."
— Confucius