Vulnerabilities > CVE-2004-2303 - Privilege Escalation vulnerability in MTools MFormat

047910
CVSS 3.6 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
mtools
nessus
exploit available

Summary

MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.

Exploit-Db

descriptionMTools 3.9.x MFormat Privilege Escalation Vulnerability. CVE-2004-2303 . Local exploit for linux platform
idEDB-ID:23759
last seen2016-02-02
modified2004-02-25
published2004-02-25
reporterSebastian Krahmer
sourcehttps://www.exploit-db.com/download/23759/
titleMTools 3.9.x - MFormat Privilege Escalation Vulnerability

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2004-016.NASL
descriptionSebastian Krahmer found that the mformat program, when installed suid root, can create any file with 0666 permissions as root, and that it also does not drop privileges when reading local configuration files. The updated packages remove the suid bit from mformat.
last seen2020-06-01
modified2020-06-02
plugin id14116
published2004-07-31
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14116
titleMandrake Linux Security Advisory : mtools (MDKSA-2004:016)