PT-2006-7586 · Suse+1 · Suse Linux Enterprise+18
Sebastian Krahmer
·
Publicado
1970-01-01
·
Atualizado
2017-07-20
·
CVE-2006-5072
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mono (affected versions not specified)
mono-core (affected versions not specified)
mono-core-32bit (affected versions not specified)
mono-core-x86 (affected versions not specified)
mono-data (affected versions not specified)
mono-data-sqlite (affected versions not specified)
mono-data-sybase (affected versions not specified)
mono-devel (affected versions not specified)
mono-extras (affected versions not specified)
mono-ikvm (affected versions not specified)
mono-jscript (affected versions not specified)
mono-locale-extras (affected versions not specified)
mono-nunit (affected versions not specified)
mono-web (affected versions not specified)
mono-winforms (affected versions not specified)
bytefx-data-mysql (affected versions not specified)
mono-basic (affected versions not specified)
Description
The issue affects multiple packages of the mono operating system, including SUSE Linux Enterprise and openSUSE, allowing for remote exploitation. This can lead to a breach of confidentiality, integrity, and availability of protected information. The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, enabling local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse Linux Enterprise
Bytefx-Data-Mysql
Mono
Mono-Basic
Mono-Core
Mono-Core-32Bit
Mono-Core-X86
Mono-Data
Mono-Data-Sqlite
Mono-Data-Sybase
Mono-Devel
Mono-Extras
Mono-Ikvm
Mono-Jscript
Mono-Locale-Extras
Mono-Nunit
Mono-Web
Mono-Winforms
Opensuse