PT-2005-2926 · Novell · Novell Netmail
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-1976
CVSS v2.0
1.7
Low
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Novell NetMail versions 3.5.2a through 3.5.2c
Description
The issue allows users or groups with a specific ID to potentially execute arbitrary code or cause a denial of service by modifying certain files. This is due to the software setting the owner and group ID to 500 for those files when running on Linux.
Recommendations
For versions 3.5.2a through 3.5.2c, consider changing the owner and group ID of the affected files to a more secure setting to prevent unauthorized access and potential code execution. As a temporary workaround, restrict access to the affected files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Netmail