PT-1998-1132 · Tiger · Tiger
Publicado
1998-06-26
·
Atualizado
2016-10-18
·
CVE-1999-1038
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tiger version 2.2.3
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the
WORKDIR variable.Recommendations
For Tiger version 2.2.3, consider restricting access to the default working directory defined by the
WORKDIR variable to prevent symlink attacks until a patch is available. As a temporary workaround, avoid using temporary files in the default working directory to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tiger