PT-2005-5324 · Ipcop · Ipcop

Juergen Schmidt

·

Publicado

2005-12-31

·

Atualizado

2017-07-20

·

CVE-2005-4659

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IPCop (aka IPCop Firewall) versions prior to 1.4.10
Description The issue allows local users to potentially overwrite system configuration files and gain privileges. This is possible by creating a malicious encrypted backup archive owned by "nobody" and then executing ipcoprscfg to restore from this backup.
Recommendations For versions prior to 1.4.10, update to version 1.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the backup.key file to prevent local users from exploiting the world-readable permissions.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4659

Produtos afetados

Ipcop