- Description
- Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.
- Source
- cve@mitre.org
- NVD status
- Deferred
CVSS 2.0
- Type
- Primary
- Base score
- 1.7
- Impact score
- 2.9
- Exploitability score
- 3.1
- Vector string
- AV:L/AC:L/Au:S/C:N/I:N/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:novell:netmail:3.5.2:a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AFAEE62-246B-4687-8B9A-A6C142D72308"
},
{
"criteria": "cpe:2.3:a:novell:netmail:3.5.2:b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21946EC8-3327-4AE6-9A0D-09C1EBCC7683"
},
{
"criteria": "cpe:2.3:a:novell:netmail:3.5.2:c:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B922B34-BBCA-4791-92EF-43ADDA7E2473"
}
],
"operator": "OR"
}
]
}
]