1.2
CVSSv2

CVE-2002-0296

Published: 31/05/2002 Updated: 11/07/2017
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 125
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

tarantella tarantella enterprise 3.10

tarantella tarantella enterprise 3.11

tarantella tarantella enterprise 3.0

tarantella tarantella enterprise 3.01

tarantella tarantella enterprise 3.20

Exploits

source: wwwsecurityfocuscom/bid/4115/info Tarantella Enterprise 3 contains a locally exploitable symbolic link vulnerability during it's installation procedure This vulnerability can be exploited to elevate privileges An attacker anticipating the install of Tarantella could create a symbolic link to any file as '/tmp/spinning' When th ...