Computer Security
[EN] securityvulns.ru no-pyccku


Enomaly ECP / Enomalism symbolic links vulnerability
updated since 01.02.2009
Published:17.02.2009
Source:
SecurityVulns ID:9638
Type:local
Threat Level:
5/10
Description:Insecure temporary files creation.
Affected:ENOMALY : Enomaly ECP 2.1
CVE:CVE-2009-0390 (Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.)
 CVE-2008-4990 (Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/enomalism2.pid temporary file.)
Original documentdocumentSam Johnston, Enomaly ECP/Enomalism: Multiple vulnerabilities in enomalism2.sh (redux) (17.02.2009)
 documentSam Johnston, CVE-2008-4990 Enomaly ECP/Enomalism: Insecure temporary file creation vulnerabilities (01.02.2009)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod