PT-2003-1473 · Sap · Sap Database
Larry W. Cashdollar
·
Publicado
2003-05-08
·
Atualizado
2016-10-18
·
CVE-2003-0265
CVSS v2.0
6.2
Média
| Vetor | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SAP database version 7.3.0.29
Description:
A race condition issue exists in SDBINST for the SAP database, where critical files are created with world-writable permissions before the setuid bits are initialized. This allows local attackers to potentially gain root privileges by modifying these files before the permissions are changed.
Recommendations:
For SAP database version 7.3.0.29, consider restricting access to the SDBINST installation process until a fix is available, and ensure that all files created during the installation have appropriate permissions set immediately to prevent unauthorized modifications.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Database