Description
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Affected products
- ingres / database_server2.5 – 2.5
- ingres / database_server2.6 – 2.6
- ingres / database_server9.0.4 – 9.0.4
- ingres / database_serverr3 – r3
References
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2288
- MISChttp://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
- VENDOR_ADVISORYhttp://secunia.com/advisories/25756
- VENDOR_ADVISORYhttp://secunia.com/advisories/25775
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2290
- MISChttp://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
- VENDOR_ADVISORYhttp://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/
- MISChttp://osvdb.org/37485
- MISChttp://www.securityfocus.com/archive/1/472200/100/0/threaded
- MISChttp://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
- MISChttp://www.securityfocus.com/bid/24585
Updated 44m ago · 2 sources