CVE-2006-4232
Published Aug 18, 2006
Last updated 7 years ago
Overview
- Description
- Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.2
- Impact score
- 2.9
- Exploitability score
- 1.9
- Vector string
- AV:L/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:globus:globus_toolkit:3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F72CDC1D-4CF8-4E8A-8A7F-1C41A21DAD92" }, { "criteria": "cpe:2.3:a:globus:globus_toolkit:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9E69418-82DA-49DD-BB34-8CD79C3BF80B" }, { "criteria": "cpe:2.3:a:globus:globus_toolkit:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FF249FE-99B9-45CC-B666-B59F2589DFC8" } ], "operator": "OR" } ] } ]