PT-2005-1921 · Openmosix · Openmosixview
Gangstuck
+1
·
Published
2005-03-29
·
Updated
2016-10-18
·
CVE-2005-0894
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenMosixView version 1.5
Description
The issue allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files in the openmosixcollector directory or nodes.tmp.
Recommendations
For OpenMosixView version 1.5, consider restricting access to the openmosixcollector directory and nodes.tmp file to prevent local users from performing symlink attacks. As a temporary workaround, consider implementing strict file system permissions to limit the ability of local users to overwrite or delete arbitrary files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openmosixview