CVE-2002-1311: Medium severity double precision incorporated courier mta vulnerability
Published Nov 29, 2002
·Updated
Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.
Affected Software
2 affected components
Double Precision Incorporated Courier Mta=0.37.3
Double Precision Incorporated Courier Mta=0.40
Remediation
Patch Available
Event History
Nov 29, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1311?
CVE-2002-1311 is considered a moderate severity vulnerability due to its potential to allow local users unauthorized access to read arbitrary files.
2
How do I fix CVE-2002-1311?
To fix CVE-2002-1311, upgrade to Courier sqwebmail version 0.40.0 or later, which addresses the privilege dropping issue.
3
Who is affected by CVE-2002-1311?
CVE-2002-1311 affects users of Courier sqwebmail versions prior to 0.40.0.
4
What type of vulnerability is CVE-2002-1311?
CVE-2002-1311 is a local privilege escalation vulnerability.
5
Can local users exploit CVE-2002-1311?
Yes, local users can exploit CVE-2002-1311 to access sensitive files due to improper privilege management.