First published: Mon Jul 23 2007(Updated: )
Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Numara Asset Manager | =8.0 | |
Centennial Discovery | =2006_featurepack1 | |
Symantec Discovery | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2950 has been classified as a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2007-2950, ensure that proper permissions are set on the affected directories to restrict local user access.
CVE-2007-2950 affects Numara Asset Manager 8.0, Centennial Discovery 2006 Feature Pack 1, and Symantec Discovery 6.5.
No, CVE-2007-2950 requires local access to the system to be exploited.
Exploiting CVE-2007-2950 can allow local users to gain elevated privileges and potentially compromise the system's security.