CVE-2009-2312: Medium severity mcafee smartfilter vulnerability
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2312?
CVE-2009-2312 is considered a high severity vulnerability due to sensitive user credentials being stored in cleartext.
How do I fix CVE-2009-2312?
To fix CVE-2009-2312, ensure that user credentials are not stored in cleartext and restrict access permissions for the config.txt file.
What are the consequences of CVE-2009-2312?
The consequences of CVE-2009-2312 include potential privilege escalation for local users exploiting the cleartext storage of credentials.
Which software versions are affected by CVE-2009-2312?
CVE-2009-2312 specifically affects McAfee SmartFilter version 4.2.1.00.
How can local users exploit CVE-2009-2312?
Local users can exploit CVE-2009-2312 by accessing the config.txt file to retrieve cleartext credentials, allowing them to gain privileged access.