PT-2001-2211 · Netscape · Netscape

Publicado

2001-08-31

·

Atualizado

2018-05-03

·

CVE-2001-1066

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Netscape versions 6.01 through 6.2.1 beta
Description The issue allows local users to overwrite arbitrary files via a symlink attack, potentially leading to unauthorized access or data modification. This is related to the ns6install installation script.
Recommendations For versions 6.01 through 6.2.1 beta, consider removing the ns6install installation script or restricting its execution to prevent exploitation until a fix is available. As a temporary workaround, monitor file system changes closely to detect potential unauthorized modifications.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1066

Produtos afetados

Netscape