7.2
CVSSv2

CVE-1999-0988

Published: 04/12/1999 Updated: 17/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 2.0.3

sco unixware 7.1

sco unixware 7.1.16

sco unixware 2.1

sco unixware 7.1.1

sco unixware 7.0

sco unixware 2.0

sco unixware 7.0.1

Exploits

source: wwwsecurityfocuscom/bid/853/info It is possible to view the entries in /etc/shadow through exploiting a buffer overflow in pkgcat and pkginstall Though neither of these binaries are setuid, the dacread permissions which are granted in /etc/security/tcb/privs give them the ability read /etc/shadow When the oversized buffer data ...