2.1

CVE-2005-4659

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IpcopIpcop Version1.4.1
IpcopIpcop Version1.4.2
IpcopIpcop Version1.4.4
IpcopIpcop Version1.4.5
IpcopIpcop Version1.4.6
IpcopIpcop Version1.4.8
IpcopIpcop Version1.4.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.252
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/17513/
Patch
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=369759
http://sourceforge.net/tracker/index.php?func=detail&aid=1344032&group_id=40604&atid=428516
http://www.securityfocus.com/bid/15377
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/23056