PT-2005-4186 · Ntop · Ntop
Published
2005-11-01
·
Updated
2011-03-08
·
CVE-2005-3387
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ntop versions prior to 3.2
Description
The issue arises from the startup script in packages/RedHat/ntop.init, which creates temporary files insecurely when ntop.conf is writable by users besides root. This allows remote attackers to execute arbitrary code.
Recommendations
For versions prior to 3.2, ensure that ntop.conf is only writable by the root user to prevent exploitation. As a temporary workaround, consider restricting access to the startup script in packages/RedHat/ntop.init until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ntop