PT-2017-14507 · Mailfilter · Assp

Michael Orlitzky

·

Publicado

2017-11-08

·

Atualizado

2020-09-16

·

CVE-2017-16659

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mail-filter/assp versions 1.9.8.13030 and earlier
Description The issue allows local users to gain privileges by leveraging access to the assp user account. This can be achieved by installing a Trojan horse /usr/share/assp/assp.pl script.
Recommendations For versions 1.9.8.13030 and earlier, update to a version later than 1.9.8.13030 to resolve the issue. As a temporary workaround, consider restricting access to the assp user account and monitoring the /usr/share/assp/assp.pl script for any unauthorized modifications.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16659

Produtos afetados

Assp