PT-2002-1282 · Oracle · Tarantella Enterprise 3

Published

2002-05-16

·

Updated

2024-02-14

·

CVE-2002-0211

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tarantella Enterprise 3 versions 3.01 through 3.20
Description A race condition exists in the installation script, which creates a world-writeable temporary "gunzip" program before executing it. This could allow local users to execute arbitrary commands by modifying the program before it is executed.
Recommendations For Tarantella Enterprise 3 versions 3.01 through 3.20, consider restricting access to the temporary directory where the "gunzip" program is created to prevent unauthorized modifications. As a temporary workaround, consider disabling the execution of the installation script until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2002-0211

Affected Products

Tarantella Enterprise 3