Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
BID:13686
Info
Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
| Bugtraq ID: | 13686 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | This issue was reported by US-CERT. |
| Vulnerable: |
Groove Networks Workspace 2.5 Groove Networks Workspace 2.0 Groove Networks Virtual Office 3.1 a Groove Networks Virtual Office 3.1 Groove Networks Virtual Office 3.0 |
| Not Vulnerable: |
Groove Networks Workspace 2.5 n build 1871 Groove Networks Virtual Office 3.1 build 2338 Groove Networks Virtual Office 3.1 a build 2364 |
Discussion
Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
Reportedly, Groove Virtual Office client installation directories are created with insecure default permissions.
This can allow an attacker to gain access to sensitive data such as authentication credentials.
Reportedly, Groove Virtual Office client installation directories are created with insecure default permissions.
This can allow an attacker to gain access to sensitive data such as authentication credentials.
Exploit / POC
Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
Solution:
The vendor has released updates to address this issue. Updates are available from the following locations:
3.x releases:
http://www.groove.net/update
2.x releases:
http://www.groove.net/archive
References
Groove Networks Groove Virtual Office Client Installation Insecure Default Permissions Vulnerability
References:
References:
- Home Page (Groove Networks)
- Vulnerability Note VU#443370 - Groove Virtual Office sets insecure permissions (CERT)