3.6
CVSSv2

CVE-1999-0825

Published: 03/12/1999 Updated: 09/09/2008
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 7.0

sco unixware 7.0.1

sco unixware 7.1

Exploits

source: wwwsecurityfocuscom/bid/849/info Certain versions of SCO's UnixWare (only 71 was tested) ship with the /var/mail/ directory with permission 777(-rwxrwxrwx) This in effect allows malicious users to read incoming mail for users who do not yet have a mail file (/var/mail/username) present This may be done by simply creating the f ...