1.2
CVSSv2

CVE-2000-0224

Published: 15/02/2000 Updated: 07/11/2023
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 125
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

ARCserve agent in SCO UnixWare 7.x allows local malicious users to gain root privileges via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sco unixware 7.1

sco unixware 7.1.1

Exploits

source: wwwsecurityfocuscom/bid/988/info A symlink following vulnerability exists in the ARCserve agent, as shipped with SCO Unixware 7 Upon startup, the asagent program will create several files in /tmp These are created mode 777, and can be removed and replaced by any user on the system If these are replaced with symlinks, files can ...