PT-2008-1950 · Sco · Sco Unixware

Qaaz

·

Publicado

2008-04-07

·

Atualizado

2017-09-29

·

CVE-2008-0310

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCO UnixWare version 7.1.4 before p534589
Description A directory traversal issue exists, allowing local users to create or append to arbitrary files. This is achieved by using ".." sequences in an unspecified environment variable, likely PKGINST, within the pkgadd environment.
Recommendations For SCO UnixWare version 7.1.4 before p534589, consider restricting access to the pkgadd command until a patch is available, specifically by limiting the ability to manipulate the environment variable that is being exploited.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0310

Produtos afetados

Sco Unixware