7.2
CVSSv2

CVE-2000-0494

Published: 16/06/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec veritas volume manager 3.0.2

symantec veritas volume manager 3.0.3

symantec veritas volume manager 3.0.4

Exploits

source: wwwsecurityfocuscom/bid/1356/info A vulnerability exists in the Volume Manager product, versions 30x, from Veritas Software Volume Manager is a popular disk management package Volume Manager running on Solaris platforms prior to Solaris 8 are vulnerable Upon startup, the /etc/rc2d/S96vmsa-server script is executed It neve ...