PT-2001-1181 · Recourse · Mantra
Published
2001-01-09
·
Updated
2017-10-10
·
CVE-2000-1145
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Recourse ManTrap version 1.6
Description
The issue allows attackers with root access to utilize utilities like crash or fsdb to read /dev/mem and raw disk devices. This access can be used to identify ManTrap processes or modify arbitrary data files.
Recommendations
For Recourse ManTrap version 1.6, consider restricting root access to prevent exploitation of this issue. As a temporary workaround, limit the use of utilities such as crash or fsdb to minimize the risk of data modification or process identification.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mantra