7.2
CVSSv2

CVE-2002-0137

Published: 25/03/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 740
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file.

Vulnerable Product Search on Vulmon Subscribe to Product

andreas mueller cdrdao 1.1.4

andreas mueller cdrdao 1.1.5

Exploits

source: wwwsecurityfocuscom/bid/3865/info CDRDAO is a freely available, open source CD recording software package available for the Unix and Linux Operating Systems It is maintained by Andreas Mueller When CDRDAO saves it's configuration to the cdrdao file in a user's home directory, the file is saved with root ownership Addition ...
source: wwwsecurityfocuscom/bid/3865/info CDRDAO is a freely available, open source CD recording software package available for the Unix and Linux Operating Systems It is maintained by Andreas Mueller When CDRDAO saves it's configuration to the cdrdao file in a user's home directory, the file is saved with root ownership Additi ...
source: wwwsecurityfocuscom/bid/3865/info CDRDAO is a freely available, open source CD recording software package available for the Unix and Linux Operating Systems It is maintained by Andreas Mueller When CDRDAO saves it's configuration to the cdrdao file in a user's home directory, the file is saved with root ownership Additional ...
source: wwwsecurityfocuscom/bid/3865/info CDRDAO is a freely available, open source CD recording software package available for the Unix and Linux Operating Systems It is maintained by Andreas Mueller When CDRDAO saves it's configuration to the cdrdao file in a user's home directory, the file is saved with root ownership Additionally ...