CVE-2005-1152: Low severity Debian Qpopper vulnerability
Published May 25, 2005
·Updated
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.
Affected Software
2 affected components
Debian Qpopper<=4.0.4
Debian Qpopper=4.0.5
Remediation
Patch Available
Event History
May 25, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1152?
CVE-2005-1152 is classified as a medium severity vulnerability due to its potential to expose files with improper permissions.
2
How do I fix CVE-2005-1152?
To fix CVE-2005-1152, update qpopper to version 4.0.5 or later to ensure proper umask settings.
3
What versions of qpopper are affected by CVE-2005-1152?
CVE-2005-1152 affects qpopper versions 4.0.5 and earlier.
4
What is the impact of CVE-2005-1152 on system security?
The impact of CVE-2005-1152 is the potential creation of files with group or world-writable permissions, leading to unauthorized access.
5
Is CVE-2005-1152 specific to any operating system?
CVE-2005-1152 primarily affects Debian-based systems that utilize the qpopper email server.