CVE-2002-1311

5 documents5 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 79.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateApr 30

Description

Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

Debiancourier< 0.40.0-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j8m5-3p5x-jmxf: Courier sqwebmail before 02022-04-30
CVEList
CVE-2002-1311: Courier sqwebmail before 02004-09-01
OSV
CVE-2002-1311: Courier sqwebmail before 02002-11-29

📋Vendor Advisories

1
Debian
CVE-2002-1311: courier - Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup i...2002
CVE-2002-1311 (MEDIUM CVSS 4.6) | Courier sqwebmail before 0.40.0 doe | cvebase.io