MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html Exploit Patch Vendor Advisory
http://www.securityfocus.com/bid/2359 Exploit Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2001-03-09T05:00:00

Updated: 2003-05-08T09:00:00

Reserved: 2001-03-08T00:00:00


Link: CVE-2001-0208

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2001-06-02T04:00:00.000

Modified: 2008-09-05T20:23:32.633


Link: CVE-2001-0208

JSON object: View

cve-icon Redhat Information

No data.