CVE-2006-4232
Summary
| CVE | CVE-2006-4232 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-18 20:04:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Globus | Globus Toolkit | 3.2.0 | All | All | All |
| Application | Globus | Globus Toolkit | 4.0.0 | All | All | All |
| Application | Globus | Globus Toolkit | 4.1.0 | All | All | All |
| Application | Globus | Globus Toolkit | 3.2.0 | All | All | All |
| Application | Globus | Globus Toolkit | 4.0.0 | All | All | All |
| Application | Globus | Globus Toolkit | 4.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] Proxy Generation Tool Vulnerability | MLIST | www.globus.org | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Globus Toolkit Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Globus Toolkit Multiple Local Temporary File Handling Vulnerabilities | BID | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690281 Free Berkeley Software Distribution (FreeBSD) Security Update for globus (5039ae61-2c9f-11db-8401-000ae42e9b93)