CVE-2007-3337: Low severity Ingres Database Server vulnerability
Published Jun 22, 2007
·Updated
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Affected Software
4 affected components
Ingres Database Server=2.5
Ingres Database Server=2.6
Ingres Database Server=9.0.4
Ingres Database Server=r3
Remediation
Event History
Jun 22, 2007
CVE Published
06:30 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3337?
CVE-2007-3337 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-3337?
To fix CVE-2007-3337, ensure that you do not use symlinks with the alarmwkp.def file and apply any available patches from Actian.
3
Which versions are affected by CVE-2007-3337?
CVE-2007-3337 affects Ingres database server versions 2.5, 2.6, 9.0.4, and r3.
4
What types of attacks does CVE-2007-3337 allow?
CVE-2007-3337 allows local users to truncate arbitrary files via a symlink attack.
5
Who is impacted by CVE-2007-3337?
Local users of the Ingres database server in multiple CA products are impacted by CVE-2007-3337.