PT-2005-4186 · Ntop · Ntop
Publicado
2005-11-01
·
Atualizado
2011-03-08
·
CVE-2005-3387
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ntop versions prior to 3.2
Description
The issue arises from the startup script in packages/RedHat/ntop.init, which creates temporary files insecurely when ntop.conf is writable by users besides root. This allows remote attackers to execute arbitrary code.
Recommendations
For versions prior to 3.2, ensure that ntop.conf is only writable by the root user to prevent exploitation. As a temporary workaround, consider restricting access to the startup script in packages/RedHat/ntop.init until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ntop