PT-2010-2658 · Perforce · Perforce Server

Published

2010-03-05

·

Updated

2010-03-08

·

CVE-2010-0935

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Perforce Server versions 2009.2 and earlier
Description The issue allows remote authenticated users to obtain super privileges via a "p4 protect" command when the protection table is empty.
Recommendations For Perforce Server versions 2009.2 and earlier, consider restricting access to the "p4 protect" command until a fix is available. As a temporary workaround, ensure the protection table is not empty to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0935

Affected Products

Perforce Server