CVE-2004-1795: Low severity Info Touch Surfnet vulnerability
Published Dec 31, 2004
·Updated
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
Affected Software
2 affected components
Info Touch Surfnet=1.31
Info Touch Surfnet=1.31
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1795?
CVE-2004-1795 is considered to be of low severity as it primarily allows local users to access the filesystem.
2
How do I fix CVE-2004-1795?
To fix CVE-2004-1795, you should apply any available updates for Info Touch Surfnet version 1.31 or implement access controls to restrict local user filesystem access.
3
Who is affected by CVE-2004-1795?
CVE-2004-1795 affects users of Info Touch Surfnet version 1.31.
4
What type of vulnerability is CVE-2004-1795?
CVE-2004-1795 is a local file access vulnerability that can be exploited through the kiosk's 'file://' URI.
5
Is there a workaround for CVE-2004-1795?
Yes, limiting local user access rights can serve as a temporary workaround for CVE-2004-1795 until a proper fix is applied.