A third-party installer generation tool, possibly BitRock InstallBuilder, as used...
Vulnerability Description
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2221
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/17804
- http://secunia.com/advisories/19954
- http://www.securityfocus.com/archive/1/432719/100/0/threaded
- http://www.securityfocus.com/archive/1/432870/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26221
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26261
- http://secunia.com/advisories/19928
- http://www.vupen.com/english/advisories/2006/1642
- http://www.vupen.com/english/advisories/2006/1659
- http://www.osvdb.org/25215
Affected Vendor
bitrock
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.