PT-2004-1421 · Ca · Etrust Inoculateit

L0Om

·

Publicado

2004-03-18

·

Atualizado

2024-02-14

·

CVE-2004-0267

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions eTrust InoculateIT for Linux version 6.0
Description The issue allows local users to overwrite arbitrary files via a symlink attack on files in /tmp, specifically through the inoregupdate, uniftest, or unimove scripts.
Recommendations For eTrust InoculateIT for Linux version 6.0, consider restricting access to the inoregupdate, uniftest, and unimove scripts to prevent local users from exploiting the symlink attack vulnerability. As a temporary workaround, restrict write access to sensitive files and directories that could be targeted by the attack.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0267

Produtos afetados

Etrust Inoculateit