// For flags

CVE-2006-4233

 

Severity Score

3.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.

Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 anterior al 15/08/2006 permite a usuarios locales obtener información sensible (certificados del proxy) y sobrescribir archivos de su elección mediante un ataque de enlace simbólico en archivos temporales en el directorio /tmp, como ha sido demostrado con archivos creados por (1) myproxy-admin-adduser, (2) grid-ca-sign, y (3) grid-security-config.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-08-18 CVE Reserved
  • 2006-08-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Globus
Search vendor "Globus"
Globus Toolkit
Search vendor "Globus" for product "Globus Toolkit"
3.2.0
Search vendor "Globus" for product "Globus Toolkit" and version "3.2.0"
-
Affected
Globus
Search vendor "Globus"
Globus Toolkit
Search vendor "Globus" for product "Globus Toolkit"
4.0.0
Search vendor "Globus" for product "Globus Toolkit" and version "4.0.0"
-
Affected
Globus
Search vendor "Globus"
Globus Toolkit
Search vendor "Globus" for product "Globus Toolkit"
4.1.0
Search vendor "Globus" for product "Globus Toolkit" and version "4.1.0"
-
Affected