First published: Sat Dec 31 2005(Updated: )
Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetMail | =3.5.2-c | |
Novell NetMail | =3.5.2-b | |
Novell NetMail | =3.5.2-a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1976 has a moderate severity rating due to its potential for arbitrary code execution and denial of service.
To fix CVE-2005-1976, ensure that the file permissions and ownerships are correctly set to prevent users with ID 500 from modifying sensitive files.
CVE-2005-1976 affects Novell NetMail versions 3.5.2a, 3.5.2b, and 3.5.2c specifically on Linux.
CVE-2005-1976 introduces vulnerabilities that could lead to unauthorized code execution and potential denial of service.
Users or groups with an owner and group ID of 500 on systems running vulnerable versions of Novell NetMail could be affected by CVE-2005-1976.