4.6
CVSSv2

CVE-2002-1311

Published: 29/11/2002 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Courier sqwebmail prior to 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

double precision incorporated courier mta 0.37.3

double precision incorporated courier mta 0.40

Vendor Advisories

A problem in the Courier sqwebmail package, a CGI program to grant authenticated access to local mailboxes, has been discovered The program did not drop permissions fast enough upon startup under certain circumstances so a local shell user can execute the sqwebmail binary and manage to read an arbitrary file on the local filesystem This problem h ...