PT-1999-1778 · Joe'S Own Editor · Joe
Publicado
1999-07-14
·
Atualizado
2016-10-18
·
CVE-1999-1545
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Joe's Own Editor (joe) version 2.8
Description:
The issue allows local users to read files that were being edited by other users, due to the world-readable permission set on the crash-save file, DEADJOE.
Recommendations:
For version 2.8, consider changing the permissions of the DEADJOE file to prevent other users from reading it, or implement access controls to restrict access to the file.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Joe