Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2007-3337 - CERT CVE
CVE-2007-3337
ID
CVE-2007-3337
Sažetak
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Reference
http://osvdb.org/37485
http://secunia.com/advisories/25756
http://secunia.com/advisories/25775
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/
http://www.securityfocus.com/archive/1/472200/100/0/threaded
http://www.securityfocus.com/bid/24585
http://www.vupen.com/english/advisories/2007/2288
http://www.vupen.com/english/advisories/2007/2290
CVSS
Base:
2.1
Impact:
2.9
Exploitability:
3.9
Pristup
Vektor
Složenost
Autentikacija
LOCAL
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
NONE
PARTIAL
NONE
CVSS vektor
AV:L/AC:L/Au:N/C:N/I:P/A:N
Zadnje važnije ažuriranje
16-10-2018 - 16:48
Objavljeno
22-06-2007 - 18:30