CVE

Id
4617  
CVE No.
CVE-2002-0225  
Status
Candidate  
Description
tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.  
Phase
Proposed (20020502)  
Votes
ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall  
Comments