CVE-2002-1970

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2002
Last modified:
05/09/2008

Description

SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snortcenter:snortcenter:0.9.5:*:*:*:*:*:*:*