7.2
CVSSv2

CVE-2002-0210

Published: 16/05/2002 Updated: 11/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

tolis group bru 17.0

Exploits

source: wwwsecurityfocuscom/bid/3970/info BRU is a commercially available backup software infrastructure available for both UNIX and Linux Operating Systems It is distributed and maintained by the Tolis Group When BRU executes, it creates temporary files insecurely BRU uses easily predicted temporary filename /tmp/brutest$$ where $$ ...