PT-2003-1055 · Ibm · Internet Message

Publicado

2003-01-08

·

Atualizado

2008-09-10

·

CVE-2002-1395

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Internet Message versions 141-18 and earlier
Description The issue allows local users to obtain unauthorized directory permissions and overwrite or create arbitrary files. This is due to the use of predictable file and directory names. There is a potential risk of integrity violation of protected information. The exploitation of this issue can be performed locally.
Recommendations For Internet Message versions 141-18 and earlier, consider restricting access to temporary directories used by impwagent and immknmz to minimize the risk of unauthorized directory permissions and arbitrary file creation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07842
CVE-2002-1395
DSA-202

Produtos afetados

Internet Message