PT-2000-1980 · Apple · Ical
Publicado
2000-12-11
·
Atualizado
2017-10-10
·
CVE-2000-1072
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
iCal version 2.1 Patch 2
Description
The issue allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse, due to world-writeable permissions of installed files.
Recommendations
For iCal version 2.1 Patch 2, change the permissions of the installed files to prevent world-writeable access, and monitor the iplncal.sh program for any unauthorized modifications.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ical