First published: Tue Dec 31 2002(Updated: )
BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jason Flatt Basic Webmail | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1711 is considered medium due to the potential for local users to access sensitive attachments.
To fix CVE-2002-1711, change the permissions of the /tmp/BasiliX directory to restrict access to only the intended users.
CVE-2002-1711 specifically affects BasiliX version 1.1.0.
Yes, local users can exploit CVE-2002-1711 to gain unauthorized access to the attachments stored in the vulnerable directory.
Using BasiliX 1.1.0 is not safe until mitigations are applied to address the directory permission issue inherent in CVE-2002-1711.