PT-2004-1421 · Ca · Etrust Inoculateit

L0Om

·

Published

2004-03-18

·

Updated

2024-02-14

·

CVE-2004-0267

CVSS v2.0
2.1
VectorAV:L/AC:L/Au:N/C:N/I:P/A:N

Name of the Vulnerable Software and Affected Versions:

eTrust InoculateIT for Linux version 6.0

Description:

The issue allows local users to overwrite arbitrary files via a symlink attack on files in /tmp, specifically through the inoregupdate, uniftest, or unimove scripts.

Recommendations:

For eTrust InoculateIT for Linux version 6.0, consider restricting access to the inoregupdate, uniftest, and unimove scripts to prevent local users from exploiting the symlink attack vulnerability. As a temporary workaround, restrict write access to sensitive files and directories that could be targeted by the attack.

Fix

Related Identifiers

CVE-2004-0267

Affected Products

Etrust Inoculateit