PT-2006-5049 · Globus · Globus Toolkit
Published
2006-08-18
·
Updated
2017-07-20
·
CVE-2006-4233
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Globus Toolkit versions 3.2.x through 4.1.0
Description
The issue allows local users to obtain sensitive information, such as proxy certificates, and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory. This can be demonstrated by files created by functions like
myproxy-admin-adduser, grid-ca-sign, and grid-security-config.Recommendations
For Globus Toolkit versions 3.2.x through 4.1.0, update to a version released after 20060815 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Globus Toolkit