Arbitrary File Read Vulnerability in Symantec Veritas File System on HP-UX and Other Platforms
CVE-2008-4638

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
21 October 2008

Summary

The Quick I/O for Database feature in Symantec Veritas File System (VxFS) contains a vulnerability that permits local users to read sensitive files. By exploiting qioadmin, users can manipulate the output to expose file contents through standard error messages, leading to potential information disclosure. This vulnerability affects users operating on HP-UX as well as those using earlier versions of VxFS on Solaris, Linux, and AIX platforms.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.