First published: Thu May 08 2014(Updated: )
NCSA Mosaic 2.0 and earlier allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/xmosaic.pid file for every possible PID.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Illinois Ncsa Mosaic | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3425 has been classified as a denial of service vulnerability.
To fix CVE-2014-3425, ensure that NCSA Mosaic is updated to a version later than 2.0.
Local users of NCSA Mosaic 2.0 and earlier are affected by CVE-2014-3425.
CVE-2014-3425 allows local users to create a denial of service by manipulating PID files.
Currently, the best workaround for CVE-2014-3425 is to remove access for unauthorized users to create files in the /tmp directory.