qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allows local users to obtain sensitive information by creating and then reading files.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/32332 | third party advisory |
http://www.securitytracker.com/id?1021074 | vdb entry |
http://www.securityfocus.com/bid/31678 | vdb entry |
http://seer.entsupport.symantec.com/docs/310872.htm | patch vendor advisory |
http://www.securityfocus.com/archive/1/497626/100/0/threaded | mailing list |
http://www.security-objectives.com/advisories/SECOBJADV-2008-04.txt | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46008 | vdb entry |
http://www.symantec.com/avcenter/security/Content/2008.10.20.html | patch vendor advisory |
http://www.security-objectives.com/advisories/SECOBJSADV-2008-04.txt | |
http://www.vupen.com/english/advisories/2008/2875 | vdb entry |