7.2
CVSSv2

CVE-1999-0014

Published: 21/01/1998 Updated: 09/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unauthorized privileged access or denial of service via dtappgather program in CDE.

Vulnerable Product Search on Vulmon Subscribe to Product

cde cde 1.02 x86

cde cde 1.02

cde cde 1.01 x86

cde cde 1.2

cde cde 1.2 x86

cde cde 1.01

ibm aix 4.3

ibm aix 4.2

hp vvos 10.24

hp hp-ux 11.00

hp hp-ux 10.20

ibm aix 4.1

hp hp-ux 10.10

Exploits

source: wwwsecurityfocuscom/bid/131/info Due to improper checking of ownership, the dtappgather utility shipped with the Common Desktop Environment allows arbitrary users to overwrite any file present on the filesystem, regardless of the owner of the file dtappgather uses a directory of permissions 0777 to create temporary files used b ...