Lucene search

K
cve[email protected]CVE-2001-1487
HistoryJun 21, 2005 - 4:00 a.m.

CVE-2001-1487

2005-06-2104:00:00
web.nvd.nist.gov
27
qualcomm qpopper 4.0
popauth utility
vulnerability
symlink attack
unauthorized access

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

Affected configurations

NVD
Node
qualcommqpopperRange4.0
CPENameOperatorVersion
qualcomm:qpopperqualcomm qpopperle4.0

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

Related for CVE-2001-1487