CVE-2007-6334: Medium severity Microsoft Windows NT vulnerability
Published Dec 20, 2007
·Updated
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
Affected Software
3 affected components
Microsoft Windows NT
Ingres Ingres=2.5
Ingres Ingres=2.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 20, 2007
CVE Published
11:46 PM
Data Sourced
11:46 PM
DescriptionWeaknessAffected Software
Dec 21, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6334?
The severity of CVE-2007-6334 is considered critical due to the potential for privilege escalation by attackers.
2
How do I fix CVE-2007-6334?
To fix CVE-2007-6334, update to a later version of Actian Ingres that addresses this privilege assignment vulnerability.
3
What systems are affected by CVE-2007-6334?
CVE-2007-6334 affects Ingres versions 2.5 and 2.6 running on Windows.
4
What is the nature of the vulnerability in CVE-2007-6334?
CVE-2007-6334 allows remote attackers to gain unauthorized privileges by exploiting the user privilege assignment flaw.
5
Who is impacted by CVE-2007-6334?
Organizations using Ingres 2.5 and 2.6 on Windows in their systems are impacted by CVE-2007-6334.