CVE-2008-3356
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which…
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ingres/ingres
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=731
- http://secunia.com/advisories/31357Vendor Advisory
- http://secunia.com/advisories/31398
- http://securitytracker.com/id?1020613
- http://www.ingres.com/support/security-alert-080108.php
- http://www.securityfocus.com/archive/1/495177/100/0/threaded
- http://www.securityfocus.com/bid/30512
- http://www.vupen.com/english/advisories/2008/2292
- http://www.vupen.com/english/advisories/2008/2313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44177
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181989
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=731
- http://secunia.com/advisories/31357Vendor Advisory
- http://secunia.com/advisories/31398
- http://securitytracker.com/id?1020613
- http://www.ingres.com/support/security-alert-080108.php
- http://www.securityfocus.com/archive/1/495177/100/0/threaded
- http://www.securityfocus.com/bid/30512
- http://www.vupen.com/english/advisories/2008/2292
- http://www.vupen.com/english/advisories/2008/2313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44177
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181989
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.