IBM Lotus Notes Lets Local Users Modify Critical Files
|
|
SecurityTracker Alert ID: 1017086 |
|
SecurityTracker URL: http://securitytracker.com/id/1017086
|
|
CVE Reference:
CVE-2005-2454
(Links to External Site)
|
Date: Oct 18 2006
|
Impact:
Modification of user information, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 6.5.4, 6.5.5, 7.0.0, 7.0.1
|
Description:
A vulnerability was reported in IBM Lotus Notes. A local user can modify Notes program and data files.
The client software installation process grants "Full Control" access privileges for the Notes program and data directory to the "Everyone" group on Windows-based systems.
A local user can add, remove, modify, or replace files in those directories.
The vendor was notified on July 22, 2005.
Carsten Eiram of Secunia Research discovered this vulnerability.
The original advisory is available at:
http://secunia.com/secunia_research/2005-29/advisory/
|
Impact:
A local user can modify Notes application and program files.
|
Solution:
The vendor has fixed the installation process for version 7.0.2. Some workarounds for previous version installations are described in the IBM advisory.
The IBM advisory is available at:
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21246773
|
Cause:
Configuration error
|
Underlying OS:
Windows (NT), Windows (2000), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 18 Oct 2006 14:20:44 -0400
Subject: Secunia 19537: IBM Lotus Notes Insecure Default Permissions
|
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21246773
CVE-2005-2454
|
|