PT-2003-1736 · Fdclone · Fdclone

Tatsuya Kinoshita

·

Publicado

2003-07-25

·

Atualizado

2016-12-08

·

CVE-2003-0596

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: FDclone versions 2.00a through 2.01
Description: The issue allows local users to read or modify files of other FDclone users by creating a temporary directory with a predictable name ahead of time. This is possible because FDclone creates temporary directories with predictable names and uses them if they already exist.
Recommendations: For FDclone versions 2.00a through 2.01, consider updating to version 2.02a or later to resolve the issue. As a temporary workaround, restrict access to the temporary directories used by FDclone to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0596
DSA-352

Produtos afetados

Fdclone