The "Protect Worksheet" functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/43764 | vdb entry |
http://securityreason.com/securityalert/3248 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37263 | vdb entry |
http://www.securityfocus.com/archive/1/482341/100/0/threaded | mailing list |