| Vulnerability Name: | CVE-2008-0310 (CCN-41759) | ||||||||
| Assigned: | 2008-04-04 | ||||||||
| Published: | 2008-04-04 | ||||||||
| Updated: | 2017-09-29 | ||||||||
| Summary: | Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.4 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
1.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-22 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-0310 Source: SCO Type: UNKNOWN SCOSA-2008.1 Source: IDEFENSE Type: UNKNOWN 20080403 SCO UnixWare pkgadd Directory Traversal Vulnerability Source: CCN Type: SA29657 SCO UnixWare "pkgadd" Directory Traversal Privilege Escalation Source: SECUNIA Type: Vendor Advisory 29657 Source: CCN Type: SECTRACK ID: 1019787 SCO UnixWare pkgadd Directory Traversal Bug Lets Local Users Gain Elevated Privileges Source: CCN Type: OSVDB ID: 43109 SCO UnixWare pkgadd Traversal Local Privilege Escalation Source: CCN Type: The SCO Group Web site The SCO Group, Inc. | Products | UnixWare 7.1.4 Source: CONFIRM Type: Patch, Vendor Advisory http://www.sco.com/support/update/download/release.php?rid=324 Source: SECTRACK Type: UNKNOWN 1019787 Source: XF Type: UNKNOWN sco-unixware-pkgadd-directory-traversal(41759) Source: XF Type: UNKNOWN sco-unixware-pkgadd-directory-traversal(41759) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 04.03.08 SCO UnixWare pkgadd Directory Traversal Vulnerability Source: EXPLOIT-DB Type: UNKNOWN 5355 | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||