7.2
CVSSv2

CVE-1999-0864

Published: 03/12/1999 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 7.1

sco unixware 7.1.1

sco unixware 7.0

sco unixware 7.0.1

Exploits

source: wwwsecurityfocuscom/bid/851/info Under certain versions of SCO UnixWare if a user can force a program with SGID (Set Group ID) to dump core they may launch a symlink attack by guessing the PID (Process ID) of the SGID process which they are calling This is required because the coredump file will be dumped to the directory in whi ...