First published: Fri Oct 12 2001(Updated: )
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =2.2.1 | |
Horde | =2.2.2 | |
Horde | =2.0 | |
Horde | <=2.2.4 | |
Horde | =2.2 | |
Horde | =2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2001-0744 is considered medium, as it allows local users to overwrite files.
To fix CVE-2001-0744, you should upgrade to Horde IMP version 2.2.5 or later.
CVE-2001-0744 affects all versions of Horde IMP up to and including 2.2.4.
No, CVE-2001-0744 can only be exploited by local users on the affected system.
The symlink attack in CVE-2001-0744 involves creating a symbolic link to manipulate temporary files used by the application.