PT-1998-1162 · Corel · Corel Word Perfect

Publicado

1998-12-18

·

Atualizado

2016-10-18

·

CVE-1999-1173

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Corel Word Perfect version 8 for Linux
Description The issue allows local users to modify the behavior of Corel Word Perfect by altering files in a temporary working directory, which has world-writable permissions. Additionally, it enables users to modify files belonging to other users through a symlink attack.
Recommendations For Corel Word Perfect version 8 for Linux, consider changing the permissions of the temporary working directory to prevent world-writable access as a temporary workaround. Restrict access to the temporary working directory to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1173

Produtos afetados

Corel Word Perfect