3.6

CVE-2004-2303

MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mtools ≫ Mformat Version 3.9.1
Mtools ≫ Mformat Version 3.9.2
Mtools ≫ Mformat Version 3.9.3
Mtools ≫ Mformat Version 3.9.4
Mtools ≫ Mformat Version 3.9.5
Mtools ≫ Mformat Version 3.9.6
Mtools ≫ Mformat Version 3.9.7
Mtools ≫ Mformat Version 3.9.8
Mtools ≫ Mformat Version 3.9.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.454
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mandriva.com/security/advisories?name=MDKSA-2004:016
Patch
Vendor Advisory
http://www.securityfocus.com/bid/9746
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15317