PT-2001-2309 · Omnisecure · Omnisecure Httprotect

Published

2001-07-19

·

Updated

2024-02-14

·

CVE-2001-1172

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OmniSecure HTTProtect version 1.1.1
Description The issue allows a superuser without omnish privileges to modify a protected file. This can be achieved by creating a symbolic link to the protected file, thereby bypassing the intended protection mechanisms.
Recommendations For OmniSecure HTTProtect version 1.1.1, consider restricting the ability to create symbolic links to protected files until a patch is available. As a temporary workaround, monitor file system changes closely to detect potential unauthorized modifications. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2001-1172

Affected Products

Omnisecure Httprotect