PT-2002-2691 · Sourcefire · Snortcenter

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1970

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SnortCenter version 0.9.5
Description The issue allows local users to obtain usernames and passwords for the alert database servers due to the storage of Snort rules in a temporary file with world-readable and world-writable permissions when SnortCenter is configured to push Snort rules.
Recommendations For SnortCenter version 0.9.5, consider changing the permissions of the temporary file used to store Snort rules to prevent world-readable and world-writable access until a patch is available. As a temporary workaround, restrict access to the temporary file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1970

Affected Products

Snortcenter