CVE-2000-1072: High severity Netscape Iplanet Ical vulnerability
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1072?
CVE-2000-1072 is considered a high severity vulnerability due to the potential for local users to execute arbitrary commands.
How do I fix CVE-2000-1072?
To fix CVE-2000-1072, you should change the permissions of the affected files to ensure they are not world-writeable.
Who is affected by CVE-2000-1072?
CVE-2000-1072 affects users of iCal 2.1 Patch 2, specifically those who have installed it with its default configuration.
What types of attacks can be performed due to CVE-2000-1072?
Exploiting CVE-2000-1072 allows local users to modify iCal's configuration and potentially launch Trojan horse attacks.
Can CVE-2000-1072 be exploited remotely?
No, CVE-2000-1072 is a local vulnerability that requires physical or local access to the affected system.