CVE-2007-6334

Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microsoft:windows_nt:*:*:*:*:*:*:*:*
OR cpe:2.3:a:ingres:ingres:2.5:*:*:*:*:*:*:*
cpe:2.3:a:ingres:ingres:2.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:39

Type Values Removed Values Added
References () http://secunia.com/advisories/28183 - Patch, Vendor Advisory () http://secunia.com/advisories/28183 - Patch, Vendor Advisory
References () http://secunia.com/advisories/28187 - Patch, Vendor Advisory () http://secunia.com/advisories/28187 - Patch, Vendor Advisory
References () http://supportconnectw.ca.com/public/ingres/infodocs/ingresmswin-secnot.asp - () http://supportconnectw.ca.com/public/ingres/infodocs/ingresmswin-secnot.asp -
References () http://www.ingres.com/support/security-alertDec17.php - () http://www.ingres.com/support/security-alertDec17.php -
References () http://www.osvdb.org/39358 - () http://www.osvdb.org/39358 -
References () http://www.securityfocus.com/archive/1/485448/100/0/threaded - () http://www.securityfocus.com/archive/1/485448/100/0/threaded -
References () http://www.securityfocus.com/bid/26959 - Patch () http://www.securityfocus.com/bid/26959 - Patch
References () http://www.securitytracker.com/id?1019134 - () http://www.securitytracker.com/id?1019134 -
References () http://www.vupen.com/english/advisories/2007/4303 - () http://www.vupen.com/english/advisories/2007/4303 -
References () http://www.vupen.com/english/advisories/2007/4304 - () http://www.vupen.com/english/advisories/2007/4304 -

Information

Published : 2007-12-20 23:46

Updated : 2024-11-21 00:39


NVD link : CVE-2007-6334

Mitre link : CVE-2007-6334

CVE.ORG link : CVE-2007-6334


JSON object : View

Products Affected

ingres

  • ingres

microsoft

  • windows_nt
CWE
CWE-264

Permissions, Privileges, and Access Controls