First published: Thu Mar 20 2008(Updated: )
Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | ||
redhat directory server | =8.0-el4 | |
redhat directory server | =8.0-el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0889 is classified as a medium severity vulnerability due to the potential for local users to execute arbitrary code.
To fix CVE-2008-0889, ensure that the permissions for the redhat-idm-console script are securely configured to restrict access.
CVE-2008-0889 affects users of Red Hat Directory Server version 8.0 running on Red Hat Enterprise Linux.
If exploited, CVE-2008-0889 allows local users to execute arbitrary code which can compromise the system's integrity.
Yes, patches are available to address CVE-2008-0889, and they should be applied to affected systems promptly.