Vulnerability Name: | CVE-2001-0744 (CCN-6640) | ||||||||
Assigned: | 2001-05-31 | ||||||||
Published: | 2001-05-31 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2001-025.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2001-025.0 Linux - imp uses /tmp unsafely Source: BUGTRAQ Type: Patch, Vendor Advisory 20010531 Imp-2.2.4 temporary files Source: CCN Type: BugTraq Mailing List, Thu May 31 2001 - 05:15:26 CDT Imp-2.2.4 temporary files Source: MITRE Type: CNA CVE-2001-0744 Source: CCN Type: Horde Web site IMP News: May Update: 2001-05-22 Source: CONFIRM Type: Patch http://www.horde.org/imp/2.2/news.php Source: CCN Type: OSVDB ID: 9528 Horde IMP from Value Race Condition Temporary File Symlink Arbitrary File Overwrite Source: CCN Type: BID-2805 Horde IMP Message Attachment Symbolic Link Vulnerability Source: CCN Type: BID-3066 Horde and Imp Temporary File Vulnerability Source: XF Type: UNKNOWN imp-attachment-filename-symlink(6640) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |