First published: Mon Dec 11 2000(Updated: )
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Iplanet Ical | =2.1-patch2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1072 is considered a high severity vulnerability due to the potential for local users to execute arbitrary commands.
To fix CVE-2000-1072, you should change the permissions of the affected files to ensure they are not world-writeable.
CVE-2000-1072 affects users of iCal 2.1 Patch 2, specifically those who have installed it with its default configuration.
Exploiting CVE-2000-1072 allows local users to modify iCal's configuration and potentially launch Trojan horse attacks.
No, CVE-2000-1072 is a local vulnerability that requires physical or local access to the affected system.