7.2
CVSSv2

CVE-2000-0048

Published: 12/01/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.

Vulnerable Product Search on Vulmon Subscribe to Product

corel linux 1.0

Exploits

source: wwwsecurityfocuscom/bid/928/info A component of the "Corel Update" utility distributed with Corel's Linux OS is vulnerable to a local PATH vulnerability The binary "get_it", which is stored in /usr/X11R6/bin, is setuid root installed by default on all Corel LinuxOS systems (it's part of their deb package install/update utils) g ...