Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
BID:31679
Info
Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
| Bugtraq ID: | 31679 |
| Class: | Design Error |
| CVE: |
CVE-2008-4638 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 20 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Derek Callaway with Security Objectives |
| Vulnerable: |
Veritas Software File System 3.5 Veritas Software File System 3.4 Veritas Software File System 3.3.3 Veritas Software File System 3.2 Veritas Software File System 5.0 Veritas Software File System 4.1 |
| Not Vulnerable: |
Veritas Software File System 5.0 MP3 |
Discussion
Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
Symantec Veritas File System (VxFS) is prone to a local information-disclosure vulnerability.
Successfully exploiting this issue allows privileged local attackers to gain access to arbitrary file contents with superuser privileges. Information harvested may aid in further attacks.
Symantec Veritas File System (VxFS) is prone to a local information-disclosure vulnerability.
Successfully exploiting this issue allows privileged local attackers to gain access to arbitrary file contents with superuser privileges. Information harvested may aid in further attacks.
Exploit / POC
Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
An attacker uses readily available tools to exploit this issue.
An attacker uses readily available tools to exploit this issue.
Solution / Fix
Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Symantec Veritas File System 'qioadmin' Local Information Disclosure Vulnerability
References:
References:
- Symantec Veritas Storage Foundation Product Page (Symantec)
- Veritas Storage Foundation Arbitrary File Read Vulnerability (Security Objectives)
- SECOBJADV-2008-05: Symantec Veritas Storage Foundation Arbitrary File Read Vulne (Security Objectives Corporation
) - SYM08-018 Veritas File System Quick I/O for Database Utility Information Disclos (Symantec)
- SYM08-018 Veritas File System Quick I/O for Database Utility Information Disclos (Symantec)