CVE-2008-3356
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.
verifydb en Ingres 2.6, Ingres 2006 versión 1 (alias 9.0.4), y Ingres 2006 versión 2 (alias 9.1.0) en Linux y otras plataformas Unix que establece la propiedad o permisos del archivo iivdb.log, sin verificar que es el archivo log propio de la aplicación, lo que permite a los usuarios sobrescribir arbitrariamente archivos creando un enlace simbólico con un nombre de archivo iivdb.log.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-07-28 CVE Reserved
- 2008-08-04 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=731 | Third Party Advisory | |
http://secunia.com/advisories/31398 | Third Party Advisory | |
http://securitytracker.com/id?1020613 | Vdb Entry | |
http://www.ingres.com/support/security-alert-080108.php | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/495177/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/30512 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2292 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2313 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44177 | Vdb Entry | |
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181989 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/31357 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ingres Search vendor "Ingres" | Ingres Search vendor "Ingres" for product "Ingres" | 2.6 Search vendor "Ingres" for product "Ingres" and version "2.6" | - |
Affected
| ||||||
Ingres Search vendor "Ingres" | Ingres Search vendor "Ingres" for product "Ingres" | 2006 Search vendor "Ingres" for product "Ingres" and version "2006" | 9.0.1 |
Affected
| ||||||
Ingres Search vendor "Ingres" | Ingres Search vendor "Ingres" for product "Ingres" | 2006 Search vendor "Ingres" for product "Ingres" and version "2006" | 9.0.4 |
Affected
| ||||||
Ingres Search vendor "Ingres" | Ingres Search vendor "Ingres" for product "Ingres" | 2006 Search vendor "Ingres" for product "Ingres" and version "2006" | release_1 |
Affected
| ||||||
Ingres Search vendor "Ingres" | Ingres Search vendor "Ingres" for product "Ingres" | 2006 Search vendor "Ingres" for product "Ingres" and version "2006" | release_2 |
Affected
|