Vulnerabilities > Ipcop > Ipcop > 1.4.5

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4660 Unspecified vulnerability in Ipcop
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.
local
high complexity
ipcop
1.2
2005-12-31 CVE-2005-4659 Information Disclosure vulnerability in IPCop Backup Key
IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.
local
low complexity
ipcop
2.1