CVE Vulnerabilities

CVE-2002-0246

Published: May 29, 2002 | Modified: Sep 11, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.

Affected Software

Name Vendor Start Version End Version
Unixware Caldera 7.1.1 (including) 7.1.1 (including)

References