PT-2001-2211 · Netscape · Netscape

Published

2001-08-31

·

Updated

2018-05-03

·

CVE-2001-1066

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Netscape versions 6.01 through 6.2.1 beta
Description The issue allows local users to overwrite arbitrary files via a symlink attack, potentially leading to unauthorized access or data modification. This is related to the ns6install installation script.
Recommendations For versions 6.01 through 6.2.1 beta, consider removing the ns6install installation script or restricting its execution to prevent exploitation until a fix is available. As a temporary workaround, monitor file system changes closely to detect potential unauthorized modifications.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1066

Affected Products

Netscape