发布时间 :2004-02-09 00:00:00
修订时间 :2016-10-17 23:06:01

[原文]eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.

[CNNVD]Computer Associates eTrust InoculateIT For Linux漏洞(CNNVD-200402-036)

        Linux 6.0版本中的eTrust InoculateIT对于许多文件和目录使用不安全权限,该目录包括应用程序的注册表和tmp目录。本地用户可以进行删除,修改,或者检查敏感信息。

- CVSS (基础分值)

CVSS分值: 4.6 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BUGTRAQ  20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux
(UNKNOWN)  BID  9616
(VENDOR_ADVISORY)  XF  etrust-inoculateit-insecure-permissions(15103)

- 公告与补丁

        Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: .

- 漏洞信息

InoculateIT Linux Insecure Directory Permissions
Local Access Required Denial of Service, Information Disclosure, Misconfiguration
Loss of Confidentiality, Loss of Integrity, Loss of Availability
Exploit Unknown

- 漏洞描述

eTrust InoculateIT contains a flaw that may allow a local user to modify files or obtain sensitive information. The issue is due to the installation writing directories with insecure permissions allowing non-privileged users to edit or delete files within. Attackers may be able to obtain sensitive information from the files as well.

- 时间线

2004-02-19 Unknow
2004-02-19 Unknow

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue. Grant only trusted users access to an affected system.

- 相关参考

