PT-2006-2301 · Symantec+1 · Symantec Ghost Solution Suite+3

Publicado

2006-03-19

·

Atualizado

2011-03-08

·

CVE-2006-1285

CVSS v2.0

3.2

Baixa

VetorAV:L/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Symantec Ghost Solutions Suite (SGSS) version 1.0 Symantec Ghost 8.0 Symantec Ghost 8.2
Description The issue allows local users to access and possibly modify certain information due to read and write permissions being given to all users for database shared memory sections in SQLAnywhere.
Recommendations For Symantec Ghost Solutions Suite (SGSS) version 1.0, consider restricting access to the database shared memory sections to prevent unauthorized modification. For Symantec Ghost 8.0, restrict access to the database shared memory sections to minimize the risk of exploitation. For Symantec Ghost 8.2, limit permissions for the database shared memory sections to only necessary users.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1285

Produtos afetados

Sqlanywhere
Symantec Ghost 8.0
Symantec Ghost 8.2
Symantec Ghost Solution Suite