PT-2006-4729 · Mysql Server+1 · Mysql Server+1

Michael Freeman

·

Published

2006-07-27

·

Updated

2018-10-17

·

CVE-2006-3878

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Opsware Network Automation System (NAS) version 6.0
Description The issue concerns insecure permissions set by Opsware Network Automation System (NAS) 6.0 on the /etc/init.d/mysql file. This allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.
Recommendations For Opsware Network Automation System (NAS) version 6.0, consider changing the permissions of the /etc/init.d/mysql file to secure it and prevent unauthorized access. As a temporary workaround, restrict access to the /etc/init.d/mysql file until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3878

Affected Products

Mysql Server
Opsware Network Automation System