First published: Tue Aug 05 2008(Updated: )
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Actian Ingres | =2006-release_2 | |
Actian Ingres | =2006-release_1 | |
Actian Ingres | =2006-9.0.1 | |
Actian Ingres | =2.6 | |
Actian Ingres | =2006-9.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3356 is considered a medium severity vulnerability due to potential local file overwrite risks.
To fix CVE-2008-3356, ensure that the ownership and permissions of the iivdb.log file are correctly set and validated before any operations.
CVE-2008-3356 affects Ingres versions 2.6, 2006 release 1 (9.0.4), and 2006 release 2 (9.1.0).
Yes, local users can exploit CVE-2008-3356 to overwrite arbitrary files due to improper validation of log file ownership.
Mitigation for CVE-2008-3356 includes applying patches provided by the vendor and enforcing strict access controls for log files.