Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6705 (WebSphere MQ)

BugsAlert Home > CVE-2007-6705 (WebSphere MQ)
 
 

The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6705

Learn more about CVE-2007-6705 (WebSphere MQ)
 
Tags: cve-2007-6705 websphere

Related Items

      bitweaver Multiple Cross-Site Scripting Vulnerabilities

      FrSIRT - Redhat Security Update Fixes Kernel CIFS Buffer Overflow Vulnerability

      CVE-2008-4668 (com_imagebrowser)

      CVE-2008-3948 (xrms_crm)

      Red Hat update for postgresql

      A Guide to Cryptography in PHP

      TROJ_AGENT.TM

 

Pixel