Описание
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-3337
- http://osvdb.org/37485
- http://secunia.com/advisories/25756
- http://secunia.com/advisories/25775
- http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
- http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation
- http://www.securityfocus.com/archive/1/472200/100/0/threaded
- http://www.securityfocus.com/bid/24585
- http://www.vupen.com/english/advisories/2007/2288
- http://www.vupen.com/english/advisories/2007/2290
EPSS
Процентиль: 22%
0.00074
Низкий
CVE ID
Связанные уязвимости
nvd
больше 18 лет назад
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
EPSS
Процентиль: 22%
0.00074
Низкий