AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-3356

MEDIUM · CVSS 4.6 EPSS 0.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-08-05 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.6. It affects Linux.

CVE
CVE-2008-3356
Severity
MEDIUM
CVSS
4.6
EPSS
0.37%
Linux

Original NVD Description

verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.