|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
OMNISecure Inc. HTTProtect contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The HTTProtect product is designed to protect files and the file system even if an external attacker gains root. The issue is triggered when a malicious user with system root privileges creates a symbolic link to a protected file. This flaw may lead to a loss of file Integrity.
|
|
Classification |
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Input Manipulation,
Misconfiguration,
Race Condition
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue. Please see the vendor's web site for more information.
|
|
Products |
|
HTTProtect
 |
1.1.1 |
|
|
|
|
|
Credit |
- TANIDA Fusao - tanida
lac.co.jp - LAC Co., Ltd.
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|