PT-2001-2677 · Mgetty · Mgetty-Viewfax+3

Publicado

1970-01-01

·

Atualizado

2017-10-10

·

CVE-2001-0141

CVSS v2.0

1.2

Baixa

VetorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions mgetty versions 1.1.22 through 1.1.25 mgetty-viewfax version 1.1.25 mgetty-sendfax version 1.1.25 mgetty-voice version 1.1.25
Description The issue allows local users to overwrite arbitrary files via a symlink attack in some configurations, potentially leading to disruption of protected information integrity. Exploitation can be carried out locally by an attacker.
Recommendations For mgetty versions 1.1.22 through 1.1.25, consider updating to a version that is not affected by this issue. For mgetty-viewfax version 1.1.25, restrict access to the package until a patch is available. For mgetty-sendfax version 1.1.25, avoid using the package in configurations where a symlink attack could be executed. For mgetty-voice version 1.1.25, consider disabling the package temporarily until a fix is provided.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02557
BDU:2015-02558
BDU:2015-02559
BDU:2015-02560
BDU:2015-02561
BDU:2015-07844
BDU:2015-07845
BDU:2015-07846
BDU:2015-07847
CVE-2001-0141

Produtos afetados

Mgetty
Mgetty-Sendfax
Mgetty-Viewfax
Mgetty-Voice