Unrated severityNVD Advisory· Published Aug 5, 2008· Updated Apr 23, 2026
CVE-2008-3356
CVE-2008-3356
Description
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.
Affected products
5cpe:2.3:a:ingres:ingres:2006:9.0.1:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:ingres:ingres:2006:9.0.1:*:*:*:*:*:*
- cpe:2.3:a:ingres:ingres:2006:9.0.4:*:*:*:*:*:*
- cpe:2.3:a:ingres:ingres:2006:release_1:*:*:*:*:*:*
- cpe:2.3:a:ingres:ingres:2006:release_2:*:*:*:*:*:*
- cpe:2.3:a:ingres:ingres:2.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/31357nvdVendor Advisory
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvd
- secunia.com/advisories/31398nvd
- securitytracker.com/idnvd
- www.ingres.com/support/security-alert-080108.phpnvd
- www.securityfocus.com/archive/1/495177/100/0/threadednvd
- www.securityfocus.com/bid/30512nvd
- www.vupen.com/english/advisories/2008/2292nvd
- www.vupen.com/english/advisories/2008/2313nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44177nvd
- support.ca.com/irj/portal/anonymous/phpsupcontentnvd
News mentions
0No linked articles in our index yet.