Vulnerability Note VU#653160

Mozilla Linux installer does not properly set file permissions

Original Release date: 17 Sep 2004 | Last revised: 17 Sep 2004

Overview

Mozilla's Linux installers may not properly set file permissions on the installed program files. A local user may then be able to modify or replace these files with malicious versions.

Description

Some versions of Mozilla's Linux installer may create installation and program files with global read and write permissions. A local user may then be able to modify or replace these files with malicious versions.

Impact

A local user may modify files, or replace files with malicious versions.

Solution

This vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.

As a workaround for older versions, modify the installed files permissions using chmod.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
MozillaAffected-17 Sep 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

Thanks to Daniel Koukola for reporting this vulnerability.

This document was written by Jason A Rafail.

Other Information

  • CVE IDs: Unknown
  • Date Public: 14 Sep 2004
  • Date First Published: 17 Sep 2004
  • Date Last Updated: 17 Sep 2004
  • Severity Metric: 10.55
  • Document Revision: 10

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.