Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Spanky

#28125de 53,633
9CVSS total
Vulnerabilidades · 2
Baixa
1
Média
1
PT-2009-3468
6.9
2009-03-12
Sun · Virtualbox · CVE-2009-0876
**Name of the Vulnerable Software and Affected Versions** Sun xVM VirtualBox versions 2.0.0 through 2.1.4 **Description** The issue allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT RPATH:$ORIGIN. **Recommendations** For versions 2.0.0 through 2.1.4, consider restricting access to the setuid/setgid bits to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2005-3944
2.1
2005-09-30
Mpeg Tools · Mpeg-Tools · CVE-2005-3115
**Name of the Vulnerable Software and Affected Versions** mpeg-tools versions prior to 1.5b-r2 **Description** The issue allows local users to overwrite arbitrary files via insecure creation of multiple temporary files, including those named ts.stat, ts.mpg, foobar, blockbar, or foobar[NNN]. **Recommendations** For versions prior to 1.5b-r2, update to version 1.5b-r2 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary file creation process to minimize the risk of exploitation.