1.2
CVSSv2

CVE-2001-1346

Published: 18/05/2001 Updated: 07/04/2021
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 130
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

ca arcserve backup 6.63

broadcom arcserve backup 6.61

Exploits

source: wwwsecurityfocuscom/bid/2741/info ARCservIT from Computer Associates contains a vulnerability which may allow malicious local users to overwrite arbitrary files When it runs for the first time, 'asagent', opens (and truncates it if it exists) a file in /tmp called 'asagenttmp' 'asagent' does not check to make sure that this fi ...
source: wwwsecurityfocuscom/bid/2748/info ARCservIT from Computer Associates contains a vulnerability which may allow malicious local users to corrupt arbitrary files When it runs with the parameters 'inet add', 'asagent', opens (and overwrites it if it exists) a file in /tmp called 'inetdtmp' 'asagent' does not check to make sure tha ...