Total vulnerabilities in the database
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
Software | From | Fixed in |
---|---|---|
ingres / database_server | 2.5 | 2.5.x |
ingres / database_server | 2.6 | 2.6.x |
ingres / database_server | 9.0.4 | 9.0.4.x |
ingres / database_server | r3 | r3.x |