Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-6594

Overview

Vulnerability Score 6.9 6.9
CVE Id CVE-2007-6594
Last Modified 07 Mar 2011 10:03:15
Published 28 Dec 2007 04:46:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity MEDIUM
Authentication NONE

CVE-2007-6594

Summary

IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.

Vulnerable Systems

Application

  • Ibm Lotus Notes 8.0.1


References

VUPEN - ADV-2007-4037

CONFIRM - http://www-1.ibm.com/support/docview.wss?uid=swg21289273

SECTRACK - 1019009

SECUNIA - 27860

OSVDB - 40934

OSVDB - 40933


Last Updated: 27 May 2016 10:46:32