PT-2005-1921 · Openmosix · Openmosixview
Gangstuck
+1
·
Publicado
2005-03-29
·
Atualizado
2016-10-18
·
CVE-2005-0894
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenMosixView version 1.5
Description
The issue allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files in the openmosixcollector directory or nodes.tmp.
Recommendations
For OpenMosixView version 1.5, consider restricting access to the openmosixcollector directory and nodes.tmp file to prevent local users from performing symlink attacks. As a temporary workaround, consider implementing strict file system permissions to limit the ability of local users to overwrite or delete arbitrary files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openmosixview