3.7
CVSSv2

CVE-2000-0409

Published: 10/05/2000 Updated: 10/09/2008
CVSS v2 Base Score: 3.7 | Impact Score: 6.4 | Exploitability Score: 1.9
VMScore: 375
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Netscape 4.73 and previous versions follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

netscape communicator 4.51

netscape communicator 4.61

netscape communicator 4.7

netscape communicator 4.72

netscape communicator 4.73

netscape communicator 4.5

netscape communicator 4.6

Exploits

source: wwwsecurityfocuscom/bid/1201/info Netscape Communicator version 473 and prior may be susceptible to a /tmp file race condition when importing certificates Netscape creates a /tmp file which is world readable and writable in /tmp, without calling stat() or fstat() on the file As such, it is possible, should a user be able to pre ...