CVE-2004-2303

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2004
Last modified:
11/07/2017

Description

MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mtools:mformat:3.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.4:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.5:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.6:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.7:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.8:*:*:*:*:*:*:*
cpe:2.3:a:mtools:mformat:3.9.9:*:*:*:*:*:*:*