PT-2008-1950 · Sco · Sco Unixware
Qaaz
·
Publicado
2008-04-07
·
Atualizado
2017-09-29
·
CVE-2008-0310
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SCO UnixWare version 7.1.4 before p534589
Description
A directory traversal issue exists, allowing local users to create or append to arbitrary files. This is achieved by using ".." sequences in an unspecified environment variable, likely
PKGINST, within the pkgadd environment.Recommendations
For SCO UnixWare version 7.1.4 before p534589, consider restricting access to the
pkgadd command until a patch is available, specifically by limiting the ability to manipulate the environment variable that is being exploited.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sco Unixware