CVE Vulnerabilities

CVE-2003-0265

Published: May 27, 2003 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.

Affected Software

Name Vendor Start Version End Version
Sap_db Sap 7.3.29 (including) 7.3.29 (including)
Sap_db Sap 7.4.3.7_beta (including) 7.4.3.7_beta (including)

References