Vulnerability Name: | CVE-2000-0722 (CCN-5129) | ||||||||
Assigned: | 2000-08-19 | ||||||||
Published: | 2000-08-19 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. | ||||||||
CVSS v3 Severity: | 8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.2 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20000820 Helix Code Security Advisory - Helix GNOME Update Source: CCN Type: BugTraq Mailing List, Sat Aug 19 2000 - 10:29:16 CDT Multiple Local Vulnerabilities in Helix Gnome Installer Source: BUGTRAQ Type: Patch, Vendor Advisory 20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer Source: CCN Type: Helix Code Security Advisory 08-20-2000-2 Helix GNOME Installer Source: MITRE Type: CNA CVE-2000-0722 Source: MITRE Type: CNA CVE-2000-0723 Source: CCN Type: OSVDB ID: 13727 Helix GNOME helix-update Arbitrary RPM Package Installation Source: CCN Type: OSVDB ID: 13728 Helix GNOME helix-update /tmp Directory Privilege Escalation Source: BID Type: Patch, Vendor Advisory 1593 Source: CCN Type: BID-1593 Gnome Updater Arbitrary RPM Installation Vulnerability Source: CCN Type: BID-1596 Gnome Installer System Config-file Overwrite Vulnerability Source: BUGTRAQ Type: UNKNOWN 20000819 Multiple Local Vulnerabilities in Helix Gnome Installer Source: XF Type: UNKNOWN gnome-installer-overwrite-configuration(5129) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |