CVE Vulnerabilities

CVE-2005-4659

Published: Dec 31, 2005 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by nobody, then executing ipcoprscfg to restore from this backup.

Affected Software

Name Vendor Start Version End Version
Ipcop Ipcop 1.4.1 (including) 1.4.1 (including)
Ipcop Ipcop 1.4.2 (including) 1.4.2 (including)
Ipcop Ipcop 1.4.4 (including) 1.4.4 (including)
Ipcop Ipcop 1.4.5 (including) 1.4.5 (including)
Ipcop Ipcop 1.4.6 (including) 1.4.6 (including)
Ipcop Ipcop 1.4.8 (including) 1.4.8 (including)
Ipcop Ipcop 1.4.9 (including) 1.4.9 (including)

References