computer vulnerability announce CVE-2007-6334

Ingres: incorrect authentication

Synthesis of the vulnerability

Under Windows, the second user who logs into Ingres is connected as the first user.
Impacted products: Ingres Database.
Severity of this bulletin: 2/4.
Consequences of an intrusion: user access/rights.
Hacker's origin: user account.
Number of vulnerabilities in this bulletin: 2.
Creation date: 20/12/2007.
Revision date: 27/12/2007.
Références of this threat: 415703, BID-2695, CAID 35970, CERTA-2007-AVI-558, CVE-2007-6334, VIGILANCE-VUL-7437.

Description of the vulnerability

The Microsoft IIS web server supports IWA (Integrated Windows Authentication) authentication. Two vulnerabilities related to this authentication affect Ingres.

With Ingres r3 and Ingres 2006, when a user is connected, and if another user authenticates, an error occurs and his access is rejected. [severity:2/4]

With Ingres 2.6 and 2.5, when a user is connected, and if another user authenticates, he accesses to the account of the first user. [severity:2/4],
