Lucene search

K
cve[email protected]CVE-2008-3357
HistoryAug 05, 2008 - 7:41 p.m.

CVE-2008-3357

2008-08-0519:41:00
CWE-426
web.nvd.nist.gov
24
cve
2008
3357
ingres
vulnerability
linux
hp-ux
shared library
pointer overwrite

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a “pointer overwrite vulnerability.”

Affected configurations

NVD
Node
actianingresMatch2.6
OR
actianingresMatch9.0.4
OR
actianingresMatch9.1.0
AND
hphp-uxMatch-
OR
linuxlinux_kernelMatch-

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%