CVE-2007-3337
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2007
Last modified:
09/04/2025
Description
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ingres:database_server:2.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ingres:database_server:2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ingres:database_server:9.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ingres:database_server:r3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/37485
- http://secunia.com/advisories/25756
- http://secunia.com/advisories/25775
- http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
- http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/
- http://www.securityfocus.com/archive/1/472200/100/0/threaded
- http://www.securityfocus.com/bid/24585
- http://www.vupen.com/english/advisories/2007/2288
- http://www.vupen.com/english/advisories/2007/2290
- http://osvdb.org/37485
- http://secunia.com/advisories/25756
- http://secunia.com/advisories/25775
- http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
- http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-ingres-file-truncation/
- http://www.securityfocus.com/archive/1/472200/100/0/threaded
- http://www.securityfocus.com/bid/24585
- http://www.vupen.com/english/advisories/2007/2288
- http://www.vupen.com/english/advisories/2007/2290



