MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/2359 | patch vendor advisory vdb entry exploit |
http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html | patch vendor advisory mailing list exploit |