6.2
CVSSv2

CVE-2000-0206

Published: 05/03/2000 Updated: 10/09/2008
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle8i 8.1.5

Exploits

source: wwwsecurityfocuscom/bid/1035/info A vulnerability exists in the installation program for Oracle 815i The Oracle installation scripts will create a directory named /tmp/orainstall, owned by oracle:dba, mode 711 Inside of this directory it will create a shell script named orainstRootsh, mode 777 The installation script will th ...