PT-2005-2926 · Novell · Novell Netmail
Publicado
2005-12-31
·
Atualizado
2008-09-05
·
CVE-2005-1976
CVSS v2.0
1.7
Baixa
| Vetor | AV:L/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Novell NetMail versions 3.5.2a through 3.5.2c
Description
The issue allows users or groups with a specific ID to potentially execute arbitrary code or cause a denial of service by modifying certain files. This is due to the software setting the owner and group ID to 500 for those files when running on Linux.
Recommendations
For versions 3.5.2a through 3.5.2c, consider changing the owner and group ID of the affected files to a more secure setting to prevent unauthorized access and potential code execution. As a temporary workaround, restrict access to the affected files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Novell Netmail