Vulnerability Description
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zero G | Installanywhere | 5.0.6 |
References
- http://secunia.com/advisories/12129Vendor Advisory
- http://vapid.dhs.org/zerogadv.txtVendor Advisory
- http://www.idefense.com/application/poi/display?id=82&type=vulnerabilitiesVendor Advisory
- http://www.osvdb.org/8236
- http://www.securityfocus.com/bid/10808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16791
- http://secunia.com/advisories/12129Vendor Advisory
- http://vapid.dhs.org/zerogadv.txtVendor Advisory
- http://www.idefense.com/application/poi/display?id=82&type=vulnerabilitiesVendor Advisory
- http://www.osvdb.org/8236
- http://www.securityfocus.com/bid/10808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16791
FAQ
What is CVE-2004-2231?
CVE-2004-2231 is a vulnerability with a CVSS score of 1.2 (LOW). Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
How severe is CVE-2004-2231?
CVE-2004-2231 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2231?
Check the references section above for vendor advisories and patch information. Affected products include: Zero G Installanywhere.