CVE
- Id
- 3029
- CVE No.
- CVE-2001-0208
- Status
- Candidate
- Description
- MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
- Phase
- Proposed (20010309)
- Votes
- ACCEPT(1) Lawler | MODIFY(1) Frech | NOOP(2) Cole, Ziese
- Comments
- Frech> XF:cobol-apptrack-nolicense-symlink(6094) | Company name is Micro Focus, a subsidiary of Merant | (http://www.merant.com/products/microfocus/)