First published: Mon Dec 31 2001(Updated: )
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Qpopper | <=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1487 has a moderate severity due to the potential for local users to exploit symlink vulnerabilities.
To fix CVE-2001-1487, upgrade to a version of Qualcomm Qpopper later than 4.0 that addresses this vulnerability.
Local users on systems running Qualcomm Qpopper version 4.0 or earlier are affected by CVE-2001-1487.
Exploiting CVE-2001-1487 allows local users to overwrite arbitrary files and execute commands as the pop user.
A symlink attack in CVE-2001-1487 involves manipulating the -trace file option to create a symbolic link that redirects file writes to unauthorized locations.