PT-2003-2086 · Ritlabs · The Bat!
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1133
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Bat! versions 1.0.11 through 2.0
Description
The issue allows local users to read other users' email messages due to insecure ACLs used when creating new accounts.
Recommendations
For versions 1.0.11 through 2.0, consider modifying the account creation process to use secure ACLs, restricting access to email messages for each user.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Bat!