CVE-2006-4232

Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:globus:globus_toolkit:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:globus:globus_toolkit:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:globus:globus_toolkit:4.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:15

Type Values Removed Values Added
References () http://secunia.com/advisories/21516 - Patch, Vendor Advisory () http://secunia.com/advisories/21516 - Patch, Vendor Advisory
References () http://www.globus.org/mail_archive/security-announce/2006/08/msg00000.html - Patch () http://www.globus.org/mail_archive/security-announce/2006/08/msg00000.html - Patch
References () http://www.securityfocus.com/bid/19549 - Patch () http://www.securityfocus.com/bid/19549 - Patch
References () http://www.vupen.com/english/advisories/2006/3290 - () http://www.vupen.com/english/advisories/2006/3290 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/28408 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/28408 -

Information

Published : 2006-08-18 20:04

Updated : 2024-11-21 00:15


NVD link : CVE-2006-4232

Mitre link : CVE-2006-4232

CVE.ORG link : CVE-2006-4232


JSON object : View

Products Affected

globus

  • globus_toolkit