7.2
CVSSv2

CVE-2002-0987

Published: 24/09/2002 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

caldera unixware 7.1.1

caldera openunix 8.0

Exploits

source: wwwsecurityfocuscom/bid/5575/info Caldera's X Server implementation invokes external commands without dropping existing privilege levels Xserver calls xkbcomp, and other related utilities, in an unsecure manner using the popen() or system() calls While this would not typically be an issue, as execution of the binary would typica ...