First published: Wed May 10 2000(Updated: )
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Communicator | =4.61 | |
Netscape Communicator | =4.73 | |
Netscape Communicator | =4.51 | |
Netscape Communicator | =4.7 | |
Netscape Communicator | =4.6 | |
Netscape Communicator | =4.72 | |
Netscape Communicator | =4.5 | |
=4.5 | ||
=4.6 | ||
=4.7 | ||
=4.51 | ||
=4.61 | ||
=4.72 | ||
=4.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0409 is classified as a medium severity vulnerability due to the potential for unauthorized file overwriting.
To fix CVE-2000-0409, ensure that you upgrade to a later version of Netscape that does not have this vulnerability.
CVE-2000-0409 affects local users of Netscape Communicator versions 4.73 and earlier.
The risks associated with CVE-2000-0409 include unauthorized access to overwrite sensitive files by local users.
A workaround for CVE-2000-0409 is to restrict local user access to the Netscape certificate import function until a fix is applied.