CVE Vulnerabilities

CVE-2002-0211

Published: May 16, 2002 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary gunzip program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

Affected Software

Name Vendor Start Version End Version
Tarantella_enterprise Tarantella 3.3.0 (including) 3.3.0 (including)
Tarantella_enterprise Tarantella 3.3.0.1 (including) 3.3.0.1 (including)
Tarantella_enterprise Tarantella 3.3.10 (including) 3.3.10 (including)
Tarantella_enterprise Tarantella 3.3.11 (including) 3.3.11 (including)
Tarantella_enterprise Tarantella 3.3.20 (including) 3.3.20 (including)

References