An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eda_agent | Eracent | * | 10.2.26 (including) |
Epa_agent | Eracent | * | 10.2.26 (including) |
Epm_agent | Eracent | * | 10.2.26 (including) |
Eua_agent | Eracent | * | 10.2.26 (including) |
Flw_agent | Eracent | * | 10.2.26 (including) |
Sum_agent | Eracent | * | 10.2.26 (including) |