Vulnerability Name:

CVE-2007-6594 (CCN-38755)

Assigned:2007-11-23
Published:2007-11-23
Updated:2011-03-08
Summary:IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2007-6594

Source: OSVDB
Type: UNKNOWN
40933

Source: OSVDB
Type: UNKNOWN
40934

Source: CCN
Type: SA27860
IBM Lotus Notes Client for Linux Insecure File Permissions

Source: SECUNIA
Type: Vendor Advisory
27860

Source: CCN
Type: SECTRACK ID: 1019009
IBM Lotus Notes for Linux Has Unsafe Folder Permissions Let Local Users Gain Root Privileges

Source: SECTRACK
Type: UNKNOWN
1019009

Source: CCN
Type: IBM News: Reference #1289273
Folder permission issues result from installer program for Notes 8 client for Linux

Source: CONFIRM
Type: UNKNOWN
http://www-1.ibm.com/support/docview.wss?uid=swg21289273

Source: CCN
Type: Linux Magazine Online Web site
Notes Client for Linux: Insecure Installation Routine

Source: CCN
Type: OSVDB ID: 40933
IBM Lotus Notes for Linux Downloaded Installation Kit Unspecified Permission Weakness

Source: CCN
Type: OSVDB ID: 40934
IBM Lotus Notes for Linux setup.sh installdata Permission Weakness Local Privilege Escalation

Source: VUPEN
Type: UNKNOWN
ADV-2007-4037

Source: XF
Type: UNKNOWN
lotus-notes-files-insecure-permissions(38755)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:lotus_notes:*:*:linux:*:*:*:*:* (Version <= 8.0.1)

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2007-6594 (CCN-38756)

    Assigned:2007-11-23
    Published:2007-11-23
    Updated:2007-11-23
    Summary:IBM Lotus Notes could allow a local attacker to gain elevated privileges, caused by insecure permissions assigned to the installdata file by the setup.sh script within the installation kit. A local attacker could exploit this vulnerability to modify the installdata file with a malicious binary, which could later be used to execute arbitrary code on the vulnerable system once setup.sh is executed.
    CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Local
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
    5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
    3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Consequences:Gain Privileges
    References:Source: MITRE
    Type: CNA
    CVE-2007-6594

    Source: CCN
    Type: SA27860
    IBM Lotus Notes Client for Linux Insecure File Permissions

    Source: CCN
    Type: SECTRACK ID: 1019009
    IBM Lotus Notes for Linux Has Unsafe Folder Permissions Let Local Users Gain Root Privileges

    Source: CCN
    Type: IBM News: Reference #1289273
    Folder permission issues result from installer program for Notes 8 client for Linux

    Source: CCN
    Type: Linux Magazine Online Web site
    Notes Client for Linux: Insecure Installation Routine

    Source: CCN
    Type: OSVDB ID: 40933
    IBM Lotus Notes for Linux Downloaded Installation Kit Unspecified Permission Weakness

    Source: CCN
    Type: OSVDB ID: 40934
    IBM Lotus Notes for Linux setup.sh installdata Permission Weakness Local Privilege Escalation

    Source: XF
    Type: UNKNOWN
    lotus-notes-setup-insecure-permission(38756)

    Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm lotus notes *
    ibm lotus notes 8.0