PT-2006-1991 · Aol · Aol 9.0 Security Edition
Carsten Eiram
·
Published
2006-08-21
·
Updated
2018-10-18
·
CVE-2006-0948
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AOL 9.0 Security Edition version 4184.2340
AOL 9.0 Security Edition (other versions, not specified)
Description
The issue concerns insecure permissions set for the "America Online 9.0" directory, allowing local users to escalate privileges by replacing critical files.
Recommendations
For AOL 9.0 Security Edition version 4184.2340, consider changing the permissions of the "America Online 9.0" directory to restrict access and prevent local users from replacing critical files.
For other affected versions of AOL 9.0 Security Edition, apply the same permission changes to the "America Online 9.0" directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aol 9.0 Security Edition