Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cluster_project | Redhat | 2.00.00 (including) | 2.00.00 (including) |
Cluster_project | Redhat | 2.01.00 (including) | 2.01.00 (including) |
Cluster_project | Redhat | 2.02.00 (including) | 2.02.00 (including) |
Cluster_project | Redhat | 2.03.00 (including) | 2.03.00 (including) |
Cluster_project | Redhat | 2.03.01 (including) | 2.03.01 (including) |
Cluster_project | Redhat | 2.03.03 (including) | 2.03.03 (including) |
Cluster_project | Redhat | 2.03.04 (including) | 2.03.04 (including) |
Cluster_project | Redhat | 2.03.05 (including) | 2.03.05 (including) |
Cluster_project | Redhat | 2.03.7 (including) | 2.03.7 (including) |
Cluster_project | Redhat | 2.03.08 (including) | 2.03.08 (including) |
Cluster_project | Redhat | 2.03.09 (including) | 2.03.09 (including) |
Cluster_project | Redhat | 2.03.10 (including) | 2.03.10 (including) |
Cluster_project | Redhat | 2.03.11 (including) | 2.03.11 (including) |
Cluster_project | Redhat | 2.99.00 (including) | 2.99.00 (including) |
Cluster_project | Redhat | 2.99.01 (including) | 2.99.01 (including) |
Cluster_project | Redhat | 2.99.02 (including) | 2.99.02 (including) |
Cluster_project | Redhat | 2.99.03 (including) | 2.99.03 (including) |
Cluster_project | Redhat | 2.99.04 (including) | 2.99.04 (including) |
Cluster_project | Redhat | 2.99.05 (including) | 2.99.05 (including) |
Cluster_project | Redhat | 2.99.06 (including) | 2.99.06 (including) |
Cluster_project | Redhat | 2.99.07 (including) | 2.99.07 (including) |
Cluster_project | Redhat | 2.99.08 (including) | 2.99.08 (including) |
Cluster_project | Redhat | 2.99.09 (including) | 2.99.09 (including) |
Cluster_project | Redhat | 2.99.10 (including) | 2.99.10 (including) |
Cluster_project | Redhat | 2.99.11 (including) | 2.99.11 (including) |
Cluster_project | Redhat | 2.99.12 (including) | 2.99.12 (including) |
Cluster_project | Redhat | 2.99.13 (including) | 2.99.13 (including) |
CLuster Suite for RHEL 4 | RedHat | rgmanager-0:1.9.88-2.el4 | * |
CLuster Suite for RHEL 4 | RedHat | ccs-0:1.0.13-2 | * |
Red Hat Enterprise Linux 5 | RedHat | rgmanager-0:2.0.52-1.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | gfs2-utils-0:0.1.62-1.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | cman-0:2.0.115-1.el5 | * |
Redhat-cluster | Ubuntu | hardy | * |
Redhat-cluster | Ubuntu | intrepid | * |
Redhat-cluster-suite | Ubuntu | dapper | * |
Redhat-cluster-suite | Ubuntu | gutsy | * |