7.2
CVSSv2

CVE-1999-1460

Published: 13/07/1999 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

BMC PATROL SNMP Agent prior to 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.

Vulnerable Product Search on Vulmon Subscribe to Product

bmc patrol agent 3.2.5

bmc patrol agent

bmc patrol agent 3.2

bmc patrol agent 3.2.3

Exploits

source: wwwsecurityfocuscom/bid/525/info Patrol 32, installed out of the box, allows for a local root compromise or denial of service The vulnerability lies in the creation of a file by snmpagnt that is owned by the owner of the parent directory of the file and possibly world writeable A local user can specify any file (/rhosts) and ...