PT-2008-1950 · Sco · Sco Unixware
Qaaz
·
Published
2008-04-07
·
Updated
2017-09-29
·
CVE-2008-0310
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SCO UnixWare version 7.1.4 before p534589
Description
A directory traversal issue exists, allowing local users to create or append to arbitrary files. This is achieved by using ".." sequences in an unspecified environment variable, likely
PKGINST, within the pkgadd environment.Recommendations
For SCO UnixWare version 7.1.4 before p534589, consider restricting access to the
pkgadd command until a patch is available, specifically by limiting the ability to manipulate the environment variable that is being exploited.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sco Unixware