PassGo Defender Local Insecure Default Directory Permissions Vulnerability
BID:20600
Info
PassGo Defender Local Insecure Default Directory Permissions Vulnerability
| Bugtraq ID: | 20600 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 19 2006 05:53PM |
| Credit: | nnposter is credited with the discovery of this vulnerability. |
| Vulnerable: |
PassGo Defender 5.2 |
| Not Vulnerable: | |
Discussion
PassGo Defender Local Insecure Default Directory Permissions Vulnerability
PassGo Defender's default settings allow local users to access the application directory and to read or modify the contents.
An attacker could exploit this issue to access and modify files stored in the application directory. This may aid in further attacks.
Version 5.2 is vulnerable; other versions may also be affected.
PassGo Defender's default settings allow local users to access the application directory and to read or modify the contents.
An attacker could exploit this issue to access and modify files stored in the application directory. This may aid in further attacks.
Version 5.2 is vulnerable; other versions may also be affected.
Exploit / POC
PassGo Defender Local Insecure Default Directory Permissions Vulnerability
No exploit is required to take advantage of this vulnerability.
No exploit is required to take advantage of this vulnerability.
Solution / Fix
PassGo Defender Local Insecure Default Directory Permissions Vulnerability
Solution:
The vendor has released a fix for this issue in a recent patch. Please see the references for information on how to obtain and apply this patch.
Solution:
The vendor has released a fix for this issue in a recent patch. Please see the references for information on how to obtain and apply this patch.
References
PassGo Defender Local Insecure Default Directory Permissions Vulnerability
References:
References:
- PassGo Defender Homepage (PassGo)
- PassGo Defender Resources and Downloads (PassGo)