First published: Tue Oct 21 2008(Updated: )
qioadmin in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, allows local users to read arbitrary files by causing qioadmin to write a file's content to standard error in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =5.0-mp2 | |
Symantec Veritas File System | =unknown-unknown |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4638 is classified as a medium severity vulnerability.
CVE-2008-4638 affects the qioadmin command within the Quick I/O for Database feature.
Local users can exploit CVE-2008-4638 to read arbitrary files by triggering error messages that display file contents.
Yes, Symantec has released updates that address the vulnerability associated with CVE-2008-4638.
CVE-2008-4638 affects Symantec Veritas File System 5.0 MP2 on HP-UX, Solaris, Linux, and AIX systems.