>> Symantec Veritas File System Information Disclosure Vulnerabilities
Title : Symantec Veritas File System Information Disclosure Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2875 CVE ID : CVE-2008-3248 - CVE-2008-4638 CWE ID : CWE-200 - CWE-264
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-10-21
Technical Description
Two vulnerabilities have been identified in Symantec Veritas File System (VxFS), which could be exploited by malicious users to gain knowledge of sensitive information.
The first issue is caused by an error in the "qiomkfile" command that allocates file system blocks to a new file without initializing those blocks, which could cause the contents of the blocks to become readable by any user that can read the new file.
The second vulnerability is caused by an error in the set-uid root "qioadmin" utility for the Quick I/O for Database feature, which could allow unprivileged users to disclose the contents of arbitrary files.