PT-2002-1282 · Oracle · Tarantella Enterprise 3
Published
2002-05-16
·
Updated
2024-02-14
·
CVE-2002-0211
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tarantella Enterprise 3 versions 3.01 through 3.20
Description
A race condition exists in the installation script, which creates a world-writeable temporary "gunzip" program before executing it. This could allow local users to execute arbitrary commands by modifying the program before it is executed.
Recommendations
For Tarantella Enterprise 3 versions 3.01 through 3.20, consider restricting access to the temporary directory where the "gunzip" program is created to prevent unauthorized modifications. As a temporary workaround, consider disabling the execution of the installation script until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tarantella Enterprise 3