{"api_version":"1","generated_at":"2026-07-23T02:33:29+00:00","cve":"CVE-2006-4232","urls":{"html":"https://cve.report/CVE-2006-4232","api":"https://cve.report/api/cve/CVE-2006-4232.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4232","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4232"},"summary":{"title":"CVE-2006-4232","description":"Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-18 20:04:00","updated_at":"2017-07-20 01:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.globus.org/mail_archive/security-announce/2006/08/msg00000.html","name":"[security-announce] 20060815 Proxy Generation Tool Vulnerability","refsource":"MLIST","tags":["Patch"],"title":"[security-announce] Proxy Generation Tool Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3290","name":"ADV-2006-3290","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28408","name":"globus-grid-proxy-race-condition(28408)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21516","name":"21516","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Globus Toolkit Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19549","name":"19549","refsource":"BID","tags":["Patch"],"title":"Globus Toolkit Multiple Local Temporary File Handling Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4232","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4232","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"3.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"4.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"4.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"3.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"4.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4232","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"globus","cpe5":"globus_toolkit","cpe6":"4.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2006-4232","qid":"690281","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for globus (5039ae61-2c9f-11db-8401-000ae42e9b93)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4232","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3290","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3290"},{"name":"globus-grid-proxy-race-condition(28408)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28408"},{"name":"[security-announce] 20060815 Proxy Generation Tool Vulnerability","refsource":"MLIST","url":"http://www.globus.org/mail_archive/security-announce/2006/08/msg00000.html"},{"name":"21516","refsource":"SECUNIA","url":"http://secunia.com/advisories/21516"},{"name":"19549","refsource":"BID","url":"http://www.securityfocus.com/bid/19549"}]}},"nvd":{"publishedDate":"2006-08-18 20:04:00","lastModifiedDate":"2017-07-20 01:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":1.2},"severity":"LOW","exploitabilityScore":1.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:globus:globus_toolkit:4.1.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:globus:globus_toolkit:3.2.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:globus:globus_toolkit:4.0.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4232","Ordinal":"19564","Title":"CVE-2006-4232","CVE":"CVE-2006-4232","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4232","Ordinal":"1","NoteData":"Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4232","Ordinal":"2","NoteData":"2006-08-18","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4232","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}