First published: Fri Dec 03 1999(Updated: )
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xinuos UnixWare | =7.0 | |
Xinuos UnixWare | =7.0.1 | |
Xinuos UnixWare | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0825 has a moderate severity level due to the potential for local users to access and modify each other's mail.
To fix CVE-1999-0825, change the permissions on the /var/mail directory to restrict access to only the intended users.
CVE-1999-0825 affects Xinuos UnixWare versions 7.0, 7.0.1, and 7.1.
Local users on the system can exploit CVE-1999-0825 due to the default permissive settings.
There is no specific patch for CVE-1999-0825; instead, it is recommended to modify the directory permissions as a remediation step.