PT-1997-1222 · Lotus · Lotus Cc:Mail
Publicado
1997-09-08
·
Atualizado
2017-12-19
·
CVE-1999-1275
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Lotus cc:Mail version 8
Description
The issue allows local users to gain privileges due to the postoffice password being stored in plaintext in a hidden file with insecure permissions.
Recommendations
For version 8, consider restricting access to the hidden file containing the postoffice password to minimize the risk of exploitation. Additionally, changing the postoffice password and ensuring proper permissions are set for the file can help mitigate the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lotus Cc:Mail