7.2
CVSSv2

CVE-1999-0014

Published: 21/01/1998 Updated: 09/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unauthorized privileged access or denial of service via dtappgather program in CDE.

Vulnerable Product Search on Vulmon Subscribe to Product

cde cde 1.02_x86

cde cde 1.2

cde cde 1.2_x86

cde cde 1.01_x86

cde cde 1.01

cde cde 1.02

ibm aix 4.1

ibm aix 4.2

ibm aix 4.3

hp hp-ux 10.20

hp vvos 10.24

hp hp-ux 10.10

hp hp-ux 11.00

Exploits

source: wwwsecurityfocuscom/bid/131/info Due to improper checking of ownership, the dtappgather utility shipped with the Common Desktop Environment allows arbitrary users to overwrite any file present on the filesystem, regardless of the owner of the file dtappgather uses a directory of permissions 0777 to create temporary files used b ...