6.2
CVSSv2

CVE-1999-0350

Published: 08/02/1999 Updated: 17/08/2022
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

Vulnerable Product Search on Vulmon Subscribe to Product

rational software clearcase 3.2

Exploits

source: wwwsecurityfocuscom/bid/538/info Rational Software's ClearCase product includes a vulnerability whereby an unprivileged user can have any readable executable set to SUID root A 15 meg file is copied and then chmod'ed to SUID, and during the time this file is being copied it can be unlinked and replaced with another Sample out ...