CVE-2008-3356
Summary
| CVE | CVE-2008-3356 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-05 19:41:00 UTC |
| Updated | 2018-10-11 20:48:00 UTC |
| Description | verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ingres | Ingres | 2.6 | All | All | All |
| Application | Ingres | Ingres | 2006 | 9.0.1 | All | All |
| Application | Ingres | Ingres | 2006 | 9.0.4 | All | All |
| Application | Ingres | Ingres | 2006 | release_1 | All | All |
| Application | Ingres | Ingres | 2006 | release_2 | All | All |
| Application | Ingres | Ingres | 2.6 | All | All | All |
| Application | Ingres | Ingres | 2006 | 9.0.1 | All | All |
| Application | Ingres | Ingres | 2006 | 9.0.4 | All | All |
| Application | Ingres | Ingres | 2006 | release_1 | All | All |
| Application | Ingres | Ingres | 2006 | release_2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ingres Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 20080801 Ingres Database for Linux verifydb Insecure File Permissions Modification Vulnerability | IDEFENSE | labs.idefense.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Support & Services | Security Alert 08.01.08 - Ingres | CONFIRM | www.ingres.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 404 Not Found | CONFIRM | support.ca.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Ingres Database Multiple Local Vulnerabilities | BID | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Ingres Database 'verifydb' Utility Lets Local Users Modify Files - SecurityTracker | SECTRACK | securitytracker.com | |
| CA Products Ingres Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.