PT-2006-2301 · Symantec+1 · Symantec Ghost Solution Suite+3
Published
2006-03-19
·
Updated
2011-03-08
·
CVE-2006-1285
CVSS v2.0
3.2
Low
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Symantec Ghost Solutions Suite (SGSS) version 1.0
Symantec Ghost 8.0
Symantec Ghost 8.2
Description
The issue allows local users to access and possibly modify certain information due to read and write permissions being given to all users for database shared memory sections in SQLAnywhere.
Recommendations
For Symantec Ghost Solutions Suite (SGSS) version 1.0, consider restricting access to the database shared memory sections to prevent unauthorized modification.
For Symantec Ghost 8.0, restrict access to the database shared memory sections to minimize the risk of exploitation.
For Symantec Ghost 8.2, limit permissions for the database shared memory sections to only necessary users.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sqlanywhere
Symantec Ghost 8.0
Symantec Ghost 8.2
Symantec Ghost Solution Suite