First published: Mon Apr 12 2004(Updated: )
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citadel | =5.90 | |
Citadel | <=6.14 | |
Citadel | =5.91 | |
Citadel | <=6.14 | |
Citadel | =5.90 | |
Citadel | =5.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-1933 is considered medium due to the potential for unauthorized message access by local users.
To fix CVE-2004-1933, modify the permissions of the database directory and files to restrict access to authorized users only.
CVE-2004-1933 affects Citadel/UX versions 5.00 through 6.14.
CVE-2004-1933 presents a local privilege escalation vulnerability due to world-readable permissions.
CVE-2004-1933 cannot be exploited remotely as it requires local access to the affected system.