First published: Fri Jun 22 2007(Updated: )
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Actian Ingres | =2.5 | |
Actian Ingres | =2.6 | |
Actian Ingres | =9.0.4 | |
Actian Ingres | =r3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3337 is classified as a medium severity vulnerability.
To fix CVE-2007-3337, ensure that you do not use symlinks with the alarmwkp.def file and apply any available patches from Actian.
CVE-2007-3337 affects Ingres database server versions 2.5, 2.6, 9.0.4, and r3.
CVE-2007-3337 allows local users to truncate arbitrary files via a symlink attack.
Local users of the Ingres database server in multiple CA products are impacted by CVE-2007-3337.