PT-2005-1921 · Openmosix · Openmosixview

Gangstuck

+1

·

Publicado

2005-03-29

·

Atualizado

2016-10-18

·

CVE-2005-0894

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenMosixView version 1.5
Description The issue allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files in the openmosixcollector directory or nodes.tmp.
Recommendations For OpenMosixView version 1.5, consider restricting access to the openmosixcollector directory and nodes.tmp file to prevent local users from performing symlink attacks. As a temporary workaround, consider implementing strict file system permissions to limit the ability of local users to overwrite or delete arbitrary files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0894

Produtos afetados

Openmosixview