6.2
CVSSv2

CVE-2002-0211

Published: 16/05/2002 Updated: 14/02/2024
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the installation script for Tarantella Enterprise 3 3.01 up to and including 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

Vulnerable Product Search on Vulmon Subscribe to Product

tarantella tarantella enterprise 3.3.10

tarantella tarantella enterprise 3.3.11

tarantella tarantella enterprise 3.3.20

tarantella tarantella enterprise 3.3.0.1

tarantella tarantella enterprise 3.3.0

Exploits

source: wwwsecurityfocuscom/bid/3966/info Tarantella Enterprise 3 is vulnerable to a race condition during the installation process During installation, a root owned binary is created in /tmp (the directory specified by the $TMPDIR environment variable) with the name gunzip#### where #### is a PID Prior to it being invoked by the instal ...