2.1
CVSSv2

CVE-2005-4659

Published: 31/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IPCop (aka IPCop Firewall) prior to 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

Vulnerable Product Search on Vulmon Subscribe to Product

ipcop ipcop 1.4.2

ipcop ipcop 1.4.4

ipcop ipcop 1.4.8

ipcop ipcop 1.4.9

ipcop ipcop 1.4.5

ipcop ipcop 1.4.6

ipcop ipcop 1.4.1