PT-2005-1921 · Openmosix · Openmosixview

Gangstuck

+1

·

Published

2005-03-29

·

Updated

2016-10-18

·

CVE-2005-0894

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenMosixView version 1.5
Description The issue allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files in the openmosixcollector directory or nodes.tmp.
Recommendations For OpenMosixView version 1.5, consider restricting access to the openmosixcollector directory and nodes.tmp file to prevent local users from performing symlink attacks. As a temporary workaround, consider implementing strict file system permissions to limit the ability of local users to overwrite or delete arbitrary files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0894

Affected Products

Openmosixview