CVE-2002-2267: High severity bogofilter Bogopass Email Filter vulnerability
bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability associated with CVE-2002-2267?
CVE-2002-2267 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file in bogofilter version 0.9.0.4.
What are the potential consequences of CVE-2002-2267?
The consequences of CVE-2002-2267 include unauthorized file modifications and potential data loss due to symlink attacks.
How can I mitigate CVE-2002-2267 in my environment?
Mitigation for CVE-2002-2267 involves upgrading to a secure version of bogofilter that does not exhibit this vulnerability, if available.
Who is affected by CVE-2002-2267?
Users of bogofilter version 0.9.0.4 are affected by CVE-2002-2267, particularly those allowing local user access.
Is CVE-2002-2267 still relevant today?
While CVE-2002-2267 is an older vulnerability, it highlights inherent risks in file handling and user permissions that are always relevant.