First published: Thu Dec 07 2006(Updated: )
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Positive Software H-Sphere Winbox | =2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6382 is considered to be a moderate severity vulnerability due to the potential for local users to exploit insecure file permissions.
To fix CVE-2006-6382, update to Positive Software H-Sphere version 2.5.0 RC3 or later to ensure proper permissions on log files.
CVE-2006-6382 is associated with a symlink attack, allowing local users to manipulate log files and append data to arbitrary files.
CVE-2006-6382 affects Positive Software H-Sphere versions prior to 2.5.0 RC3, including 2.4.3.
Local users on systems running affected versions of Positive Software H-Sphere can exploit CVE-2006-6382 to compromise system integrity.