CVE-2006-1285
Summary
| CVE | CVE-2006-1285 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-19 23:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information. |
Risk And Classification
Primary CVSS: v2.0 3.2 from [email protected]
AV:L/AC:L/Au:S/C:P/I:P/A:N
EPSS: 0.001620000 probability, percentile 0.371320000 (date 2026-04-17)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Ghost Solutions Suite | 1.0 | All | All | All |
| Application | Symantec | Norton Ghost | 8.0 | All | All | All |
| Application | Symantec | Norton Ghost | 8.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Symantec Ghost Underlying Database Bugs May Let Local Users Access the Database | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Symantec Ghost Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Symantec Ghost SQLAnywhere Local Information Disclosure and Data Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Symantec Ghost: Local access vulnerabilities in Database | af854a3a-2127-422b-91ae-364da2661108 | securityresponse.symantec.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.