PT-2002-2691 · Sourcefire · Snortcenter

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1970

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SnortCenter version 0.9.5
Description The issue allows local users to obtain usernames and passwords for the alert database servers due to the storage of Snort rules in a temporary file with world-readable and world-writable permissions when SnortCenter is configured to push Snort rules.
Recommendations For SnortCenter version 0.9.5, consider changing the permissions of the temporary file used to store Snort rules to prevent world-readable and world-writable access until a patch is available. As a temporary workaround, restrict access to the temporary file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1970

Produtos afetados

Snortcenter