PT-2003-1055 · Ibm · Internet Message

Published

2003-01-08

·

Updated

2008-09-10

·

CVE-2002-1395

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Internet Message versions 141-18 and earlier
Description The issue allows local users to obtain unauthorized directory permissions and overwrite or create arbitrary files. This is due to the use of predictable file and directory names. There is a potential risk of integrity violation of protected information. The exploitation of this issue can be performed locally.
Recommendations For Internet Message versions 141-18 and earlier, consider restricting access to temporary directories used by impwagent and immknmz to minimize the risk of unauthorized directory permissions and arbitrary file creation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07842
CVE-2002-1395
DSA-202

Affected Products

Internet Message