PT-2008-1950 · Sco · Sco Unixware

Qaaz

·

Published

2008-04-07

·

Updated

2017-09-29

·

CVE-2008-0310

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCO UnixWare version 7.1.4 before p534589
Description A directory traversal issue exists, allowing local users to create or append to arbitrary files. This is achieved by using ".." sequences in an unspecified environment variable, likely PKGINST, within the pkgadd environment.
Recommendations For SCO UnixWare version 7.1.4 before p534589, consider restricting access to the pkgadd command until a patch is available, specifically by limiting the ability to manipulate the environment variable that is being exploited.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0310

Affected Products

Sco Unixware