Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Linux, uses world-readable and world-writable permissions for /etc/csia_config.xml, which allows local users to change CSI Agent configuration by modifying this file.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/64775 | vdb entry third party advisory |
http://secunia.com/vulnerability_scanning/corporate/release-history/ | third party advisory |
http://osvdb.org/101901 | vdb entry broken link |
http://secunia.com/advisories/56380 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90230 | vdb entry third party advisory |