CVE Vulnerabilities

CVE-2002-1199

Published: Oct 28, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.

Affected Software

NameVendorStart VersionEnd Version
OpenlinuxCaldera2.2 (including)2.2 (including)
OpenlinuxCaldera2.3 (including)2.3 (including)
OpenlinuxCaldera2.4 (including)2.4 (including)
OpenserverSco5.0.5 (including)5.0.5 (including)
OpenserverSco5.0.6 (including)5.0.6 (including)
OpenserverSco5.0.6a (including)5.0.6a (including)
SolarisSun9.0 (including)9.0 (including)
SunosSun5.7 (including)5.7 (including)
SunosSun5.8 (including)5.8 (including)

References