PT-1998-1162 · Corel · Corel Word Perfect
Published
1998-12-18
·
Updated
2016-10-18
·
CVE-1999-1173
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Corel Word Perfect version 8 for Linux
Description
The issue allows local users to modify the behavior of Corel Word Perfect by altering files in a temporary working directory, which has world-writable permissions. Additionally, it enables users to modify files belonging to other users through a symlink attack.
Recommendations
For Corel Word Perfect version 8 for Linux, consider changing the permissions of the temporary working directory to prevent world-writable access as a temporary workaround. Restrict access to the temporary working directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corel Word Perfect