CVE-2005-2454 Information

Description

IBM Lotus Notes 6.5.4 and 6.5.5 and 7.0.0 and 7.0.1 uses insecure default permissions (Everyone/Full Control) for the \Notes\ folder and all children which allows local users to gain privileges and modify add or delete files in that folder.

Reference

http://secunia.com/advisories/19537 http://secunia.com/advisories/27342 http://secunia.com/secunia_research/2005-29/advisory/ http://securitytracker.com/id?1017086 http://www.kb.cert.org/vuls/id/383092 http://www.osvdb.org/29761 http://www.securityfocus.com/archive/1/449126/100/0/threaded http://www.securityfocus.com/bid/20612 http://www.vupen.com/english/advisories/2006/4093 http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21246773 https://exchange.xforce.ibmcloud.com/vulnerabilities/29660

Share on: