PT-2002-1027 · Dump · Dump

CVE-2002-1914

·

Publicado

2002-12-31

·

Atualizado

2024-02-08

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dump versions 0.4 b10 through 0.4 b29
Description The issue allows local users to cause a denial of service, preventing execution, by using the flock() function to lock the /etc/dumpdates file. This can lead to a disruption in the availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For dump versions 0.4 b10 through 0.4 b29, consider restricting access to the /etc/dumpdates file to prevent the flock() function from locking it, until a patch is available. As a temporary workaround, avoid using the flock() function to lock the /etc/dumpdates file.

Correção

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06667
BDU:2015-06671
CVE-2002-1914

Produtos afetados

Dump