MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.Referenceshttp://www.mandriva.com/security/advisories?name=MDKSA-2004:016https://exchange.xforce.ibmcloud.com/vulnerabilities/15317http://www.securityfocus.com/bid/9746