CVE-2010-0935: Medium severity Perforce Perforce Server vulnerability
Published Mar 5, 2010
·Updated
Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.
Affected Software
23 affected components
Perforce Perforce Server=2008.1
Perforce Perforce Server=2007.3
Perforce Perforce Server=2002.2
Perforce Perforce Server=2000.2
Perforce Perforce Server<=2009.2
Perforce Perforce Server=2006.1
Perforce Perforce Server=2001.2
Perforce Perforce Server=99.2
Perforce Perforce Server=2007.2
Perforce Perforce Server=2004.2
Perforce Perforce Server=2005.1
Perforce Perforce Server=2005.2
Perforce Perforce Server=2000.1
Perforce Perforce Server=2001.1
Perforce Perforce Server=2002.1
Perforce Perforce Server=99.1
Perforce Perforce Server=2007.3_143793
Perforce Perforce Server=2003.1
Perforce Perforce Server=97.3
Perforce Perforce Server=2006.2
Perforce Perforce Server=98.2
Perforce Perforce Server=2003.2
Perforce Perforce Server=2008.2
Event History
Mar 5, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0935?
CVE-2010-0935 has a medium severity rating as it allows remote authenticated users to gain super privileges.
2
How do I fix CVE-2010-0935?
To fix CVE-2010-0935, ensure that the protection table is properly configured to avoid granting super-user privileges.
3
What versions of Perforce Server are affected by CVE-2010-0935?
CVE-2010-0935 affects Perforce Server versions up to and including 2009.2.
4
What impact does CVE-2010-0935 have on system security?
CVE-2010-0935 can lead to unauthorized access and manipulation of the server by granting super-user rights to authenticated users.
5
Is authentication enough to secure Perforce Server against CVE-2010-0935?
No, simply authenticating users is not sufficient; proper configuration of the protection table is necessary to mitigate CVE-2010-0935.