Vulnerability Name: | CVE-2000-0723 (CCN-5129) | ||||||||
Assigned: | 2000-08-19 | ||||||||
Published: | 2000-08-19 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | ||||||||
CVSS v3 Severity: | 8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sat Aug 19 2000 - 10:29:16 CDT Multiple Local Vulnerabilities in Helix Gnome Installer Source: BUGTRAQ Type: Patch, Vendor Advisory 20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer Source: CCN Type: Helix Code Security Advisory 08-20-2000-2 Helix GNOME Installer Source: MITRE Type: CNA CVE-2000-0722 Source: MITRE Type: CNA CVE-2000-0723 Source: CCN Type: OSVDB ID: 13727 Helix GNOME helix-update Arbitrary RPM Package Installation Source: CCN Type: OSVDB ID: 13728 Helix GNOME helix-update /tmp Directory Privilege Escalation Source: CCN Type: BID-1593 Gnome Updater Arbitrary RPM Installation Vulnerability Source: BID Type: Patch, Vendor Advisory 1596 Source: CCN Type: BID-1596 Gnome Installer System Config-file Overwrite Vulnerability Source: BUGTRAQ Type: UNKNOWN 20000819 Multiple Local Vulnerabilities in Helix Gnome Installer Source: XF Type: UNKNOWN gnome-installer-overwrite-configuration(5129) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |