CVE Database
/

CVE-2008-3356

Back to search

CVE-2008-3356

Published: Aug 5, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2008-2292
vdb-entry
x_refsource_VUPEN
31398
third-party-advisory
x_refsource_SECUNIA
1020613
vdb-entry
x_refsource_SECTRACK
ADV-2008-2313
vdb-entry
x_refsource_VUPEN
31357
third-party-advisory
x_refsource_SECUNIA
ingres-verifydb-symlink(44177)
vdb-entry
x_refsource_XF
30512
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now