CVE-2001-0744: Low severity Horde IMP vulnerability
Published Oct 12, 2001
·Updated
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.
Affected Software
6 affected components
Horde IMP=2.2.1
Horde IMP=2.2.2
Horde IMP=2.0
Horde IMP<=2.2.4
Horde IMP=2.2
Horde IMP=2.2.3
Remediation
Patch Available
Event History
Oct 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0744?
The severity of CVE-2001-0744 is considered medium, as it allows local users to overwrite files.
2
How do I fix CVE-2001-0744?
To fix CVE-2001-0744, you should upgrade to Horde IMP version 2.2.5 or later.
3
What systems are affected by CVE-2001-0744?
CVE-2001-0744 affects all versions of Horde IMP up to and including 2.2.4.
4
Can remote attackers exploit CVE-2001-0744?
No, CVE-2001-0744 can only be exploited by local users on the affected system.
5
What does the symlink attack in CVE-2001-0744 involve?
The symlink attack in CVE-2001-0744 involves creating a symbolic link to manipulate temporary files used by the application.