Vulnerabilities > CVE-2004-2303 - Unspecified vulnerability in Mtools Mformat

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
mtools
nessus
exploit available

Summary

MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.

Exploit-Db

descriptionMTools 3.9.x MFormat Privilege Escalation Vulnerability. CVE-2004-2303 . Local exploit for linux platform
idEDB-ID:23759
last seen2016-02-02
modified2004-02-25
published2004-02-25
reporterSebastian Krahmer
sourcehttps://www.exploit-db.com/download/23759/
titleMTools 3.9.x - MFormat Privilege Escalation Vulnerability

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2004-016.NASL
descriptionSebastian Krahmer found that the mformat program, when installed suid root, can create any file with 0666 permissions as root, and that it also does not drop privileges when reading local configuration files. The updated packages remove the suid bit from mformat.
last seen2020-06-01
modified2020-06-02
plugin id14116
published2004-07-31
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14116
titleMandrake Linux Security Advisory : mtools (MDKSA-2004:016)