|
ICQ Lite Insecure File Permissions
|
|
Secunia Advisory:
|
SA8906
|
|
|
Release Date:
|
2003-06-02
|
|
Popularity:
|
6,242 views
|
|
|
Critical:
|
 Not critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Unpatched
|
|
| Software: | ICQ Lite
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: A vulnerability has been identified in ICQ Lite, which allows malicious, local users to overwrite the executable.
The problem is that when ICQ Lite is installed, it will change the file permissions on the ICQ Lite folder under "Program Files".
This only affects Windows systems using NTFS, as this is always possible on systems using FAT.
Solution: Change the permissions on the ICQ Lite folder so that only Administrator can change and write to the files.
Provided and/or discovered by: 3APA3A
Original Advisory: http://www.security.nnov.ru/advisories/icqlite.asp
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|