Vulnerabilities > CVE-2004-2611 - Unspecified vulnerability in Steven Schaefer Sophster
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
References
- http://securitytracker.com/id?1010431
- http://securitytracker.com/id?1010431
- http://www.osvdb.org/6657
- http://www.osvdb.org/6657
- http://www.schaefer.dhcp.biz/CHANGELOG.txt
- http://www.schaefer.dhcp.biz/CHANGELOG.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16359
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16359