CVE Vulnerabilities

CVE-2002-0225

Published: May 16, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.

Affected Software

Name Vendor Start Version End Version
Tacacs+ Cisco f4.0.4alpha (including) f4.0.4alpha (including)

References