10
CVSSv2

CVE-1999-0836

Published: 02/12/1998 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 7.1

sco unixware 7.1.1

sco unixware 7.0

sco unixware 7.0.1

Exploits

source: wwwsecurityfocuscom/bid/842/info Certain versions of SCO Unixware ship with an exploitable version of the /usr/bin/uidadmin program The problem lies in that 'uidadmin' runs with root privileges and performs insecure writes to a scratch directory (/tmp/ in this instance) A malicious user may overwrite any existing file on the sys ...