|
|
|
![]() |
Vulnerability Note VU#653160Mozilla Linux installer does not properly set file permissionsOverviewMozilla's Linux installers may not properly set file permissions on the installed program files. A local user may then be able to modify or replace these files with malicious versions.I. DescriptionSome versions of Mozilla's Linux installer may create installation and program files with global read and write permissions. A local user may then be able to modify or replace these files with malicious versions.II. ImpactA local user may modify files, or replace files with malicious versions.III. SolutionThis vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.As a workaround for older versions, modify the installed files permissions using chmod.
References
Thanks to Daniel Koukola for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||