CVE-2006-4232: Race Condition
Published Aug 18, 2006
·Updated
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.
Affected Software
3 affected components
globus Globus Toolkit=3.2.0
globus Globus Toolkit=4.0.0
globus Globus Toolkit=4.1.0
Remediation
Patch Available
Patch Available
Event History
Aug 18, 2006
CVE Published
08:04 PM
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4232?
CVE-2006-4232 has a medium severity rating due to its local exploitation potential.
2
How do I fix CVE-2006-4232?
To fix CVE-2006-4232, ensure you update Globus Toolkit to a version later than 20060815.
3
What systems are affected by CVE-2006-4232?
CVE-2006-4232 affects Globus Toolkit versions 3.2.x, 4.0.x, and 4.1.0 prior to 20060815.
4
What does CVE-2006-4232 exploit?
CVE-2006-4232 exploits a race condition that allows local users to replace the proxy credentials file.
5
Can CVE-2006-4232 be exploited remotely?
No, CVE-2006-4232 requires local access to exploit the vulnerability.