search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Mozilla Linux installer does not properly set file permissions

Vulnerability Note VU#653160

Original Release Date: 2004-09-17 | Last Revised: 2004-09-17

Overview

Mozilla's Linux installers may not properly set file permissions on the installed program files. A local user may then be able to modify or replace these files with malicious versions.

Description

Some versions of Mozilla's Linux installer may create installation and program files with global read and write permissions. A local user may then be able to modify or replace these files with malicious versions.

Impact

A local user may modify files, or replace files with malicious versions.

Solution

This vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.

As a workaround for older versions, modify the installed files permissions using chmod.

Vendor Information

653160
 

Mozilla Affected

Updated:  September 17, 2004

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

This vulnerability is resolved in Firefox Preview Release, Mozilla 1.7.3, and Thunderbird 0.8.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Daniel Koukola for reporting this vulnerability.

This document was written by Jason A Rafail.

Other Information

CVE IDs: None
Severity Metric: 10.55
Date Public: 2004-09-14
Date First Published: 2004-09-17
Date Last Updated: 2004-09-17 18:02 UTC
Document Revision: 11

Sponsored by CISA.