IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
BID:20612
Info
IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
| Bugtraq ID: | 20612 |
| Class: | Design Error |
| CVE: |
CVE-2005-2454 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 25 2007 08:36PM |
| Credit: | Carsten Eiram of Secunia Research is credited with the discovery of this vulnerability. |
| Vulnerable: |
IBM Lotus Notes 7.0.1 IBM Lotus Notes 6.5.5 IBM Lotus Notes 6.5.4 IBM Lotus Notes 8.0 IBM Lotus Notes 7.0 |
| Not Vulnerable: |
IBM Lotus Notes 7.0.2 |
Discussion
IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
IBM Lotus Notes is prone to a vulnerability regarding insecure default permissions on the application directory.
A local attacker can exploit this issue to access and modify arbitrary files in the application directory; this may aid in further attacks.
IBM Lotus Notes is prone to a vulnerability regarding insecure default permissions on the application directory.
A local attacker can exploit this issue to access and modify arbitrary files in the application directory; this may aid in further attacks.
Exploit / POC
IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
To exploit this issue, an attacker simply requires local access to a vulnerable computer.
To exploit this issue, an attacker simply requires local access to a vulnerable computer.
Solution / Fix
IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
Solution:
The vendor has released a patch to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released a patch to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
IBM Lotus Notes Local Insecure Default Directory Permissions Vulnerability
References:
References: