cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.
References
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2008-09-05 13:33
NVD link : CVE-2002-2382
Mitre link : CVE-2002-2382
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
cvsup
- cvsup