First published: Tue Oct 21 2008(Updated: )
qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allows local users to obtain sensitive information by creating and then reading files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =unknown-unknown |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3248 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
To mitigate CVE-2008-3248, upgrade to Symantec Veritas File System version 5.0 MP3 or later where the issue is resolved.
CVE-2008-3248 affects Symantec Veritas File System version 5.0 MP2 on HP-UX, Solaris, Linux, and AIX.
The impact of CVE-2008-3248 allows local users to read sensitive information from filesystem blocks that are not initialized during file creation.
CVE-2008-3248 can be exploited by local users who have the ability to create files on the affected systems.