CVE
- Id
- 3975
- CVE No.
- CVE-2001-1171
- Status
- Candidate
- Description
- Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
- Phase
- Proposed (20020315)
- Votes
- ACCEPT(1) Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | REJECT(2) Christey, Frech
- Comments
- Frech> Both candidates assigned to XF:fw1-tmp-file-symlink(7094); | CVE-2001-1171 has subset of references in CVE-201-1102. | Christey> Agreed, it"s a dupe. CVE-2001-1102 will be preferred, since | it has more complete references.