2.1
CVE-2006-2221
- EPSS 0.37%
- Veröffentlicht 05.05.2006 19:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitrock ≫ Install Builder Version <= 3.6.0
Process-one ≫ Ejabberd Version <= 1.1.1.1
Process-one ≫ Ejabberd Version1.1.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.287 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|
http://secunia.com/advisories/19928
http://secunia.com/advisories/19954
http://www.osvdb.org/25215
http://www.securityfocus.com/archive/1/432719/100/0/threaded
http://www.securityfocus.com/archive/1/432870/100/0/threaded
http://www.securityfocus.com/bid/17804
http://www.vupen.com/english/advisories/2006/1642
http://www.vupen.com/english/advisories/2006/1659
https://exchange.xforce.ibmcloud.com/vulnerabilities/26221
https://exchange.xforce.ibmcloud.com/vulnerabilities/26261