PT-2001-2211 · Netscape · Netscape
Publicado
2001-08-31
·
Atualizado
2018-05-03
·
CVE-2001-1066
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Netscape versions 6.01 through 6.2.1 beta
Description
The issue allows local users to overwrite arbitrary files via a symlink attack, potentially leading to unauthorized access or data modification. This is related to the ns6install installation script.
Recommendations
For versions 6.01 through 6.2.1 beta, consider removing the ns6install installation script or restricting its execution to prevent exploitation until a fix is available. As a temporary workaround, monitor file system changes closely to detect potential unauthorized modifications.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netscape