PT-2006-2301 · Symantec+1 · Symantec Ghost Solution Suite+3

Published

2006-03-19

·

Updated

2011-03-08

·

CVE-2006-1285

CVSS v2.0

3.2

Low

VectorAV:L/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Symantec Ghost Solutions Suite (SGSS) version 1.0 Symantec Ghost 8.0 Symantec Ghost 8.2
Description The issue allows local users to access and possibly modify certain information due to read and write permissions being given to all users for database shared memory sections in SQLAnywhere.
Recommendations For Symantec Ghost Solutions Suite (SGSS) version 1.0, consider restricting access to the database shared memory sections to prevent unauthorized modification. For Symantec Ghost 8.0, restrict access to the database shared memory sections to minimize the risk of exploitation. For Symantec Ghost 8.2, limit permissions for the database shared memory sections to only necessary users.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1285

Affected Products

Sqlanywhere
Symantec Ghost 8.0
Symantec Ghost 8.2
Symantec Ghost Solution Suite