{"api_version":"1","generated_at":"2026-07-23T07:12:21+00:00","cve":"CVE-2005-1976","urls":{"html":"https://cve.report/CVE-2005-1976","api":"https://cve.report/api/cve/CVE-2005-1976.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1976","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1976"},"summary":{"title":"CVE-2005-1976","description":"Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:N/I:N/A:P","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm","name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14005","name":"http://www.securityfocus.com/bid/14005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Novell NetMail Patch Packaging Insecure File Permissions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/15763","name":"http://secunia.com/advisories/15763","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Novell NetMail File Ownership Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/17456","name":"http://www.osvdb.org/17456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1014251","name":"http://securitytracker.com/id?1014251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Novell NetMail for Linux Access Permissions May Let Local Users Modify the Binaries","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1976","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1976","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1976","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"netmail","cpe6":"3.5.2","cpe7":"a","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1976","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"netmail","cpe6":"3.5.2","cpe7":"b","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1976","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"netmail","cpe6":"3.5.2","cpe7":"c","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.724Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"14005","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14005"},{"name":"15763","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15763"},{"name":"17456","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/17456"},{"name":"1014251","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014251"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-06-05T18:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"14005","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14005"},{"name":"15763","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15763"},{"name":"17456","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/17456"},{"name":"1014251","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014251"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1976","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"14005","refsource":"BID","url":"http://www.securityfocus.com/bid/14005"},{"name":"15763","refsource":"SECUNIA","url":"http://secunia.com/advisories/15763"},{"name":"17456","refsource":"OSVDB","url":"http://www.osvdb.org/17456"},{"name":"1014251","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014251"},{"name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm","refsource":"CONFIRM","url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1976","datePublished":"2006-06-05T18:00:00.000Z","dateReserved":"2005-06-16T00:00:00.000Z","dateUpdated":"2024-09-16T19:50:43.890Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:N/I:N/A:P","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:netmail:3.5.2:a:*:*:*:*:*:*","matchCriteriaId":"6AFAEE62-246B-4687-8B9A-A6C142D72308"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:netmail:3.5.2:b:*:*:*:*:*:*","matchCriteriaId":"21946EC8-3327-4AE6-9A0D-09C1EBCC7683"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:netmail:3.5.2:c:*:*:*:*:*:*","matchCriteriaId":"0B922B34-BBCA-4791-92EF-43ADDA7E2473"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1976","Ordinal":"1","Title":"CVE-2005-1976","CVE":"CVE-2005-1976","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1976","Ordinal":"1","NoteData":"Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.","Type":"Description","Title":"CVE-2005-1976"},{"CveYear":"2005","CveId":"1976","Ordinal":"2","NoteData":"2006-06-05","Type":"Other","Title":"Published"}]}}}