PT-2001-2211 · Netscape · Netscape
Published
2001-08-31
·
Updated
2018-05-03
·
CVE-2001-1066
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Netscape versions 6.01 through 6.2.1 beta
Description
The issue allows local users to overwrite arbitrary files via a symlink attack, potentially leading to unauthorized access or data modification. This is related to the ns6install installation script.
Recommendations
For versions 6.01 through 6.2.1 beta, consider removing the ns6install installation script or restricting its execution to prevent exploitation until a fix is available. As a temporary workaround, monitor file system changes closely to detect potential unauthorized modifications.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netscape