7.2
CVSSv2

CVE-2002-1514

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.

Vulnerable Product Search on Vulmon Subscribe to Product

borland software interbase 6.5

borland software interbase 5.0

borland software interbase 4.0

borland software interbase 6.0

Exploits

source: wwwsecurityfocuscom/bid/5805/info Interbase is a SQL database distributed and maintained by Borland It is available for Unix and Linux operating systems The gds_lock_mgr program within Interbase is typically installed setuid This program does not properly handle user-supplied umasks, and may allow the creation of files with in ...