CVE-2002-1311 describes a privilege escalation vulnerability in Courier sqwebmail versions prior to 0.40.0, specifically affecting double_precision_incorporated courier_mta. The flaw stems from the application's failure to promptly drop privileges after startup in certain scenarios. This oversight could enable local attackers to read arbitrary files on the system. The vulnerability has a CVSS score of 4.6, indicating a medium severity. It requires local access (AV:L), has low attack complexity (AC:L), and does not require authentication (Au:N). The potential impact includes confidentiality, integrity, and availability compromises (C:P/I:P/A:P). There is no evidence of active exploitation, nor are there known exploits available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media mentions or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.37.3CPE matchmatch criteria | cpe:2.3:a:double_precision_incorporated:courier_mta:0.37.3:*:*:*:*:*:*:* | ||
0.40CPE matchmatch criteria | cpe:2.3:a:double_precision_incorporated:courier_mta:0.40:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.