cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html | Exploit Vendor Advisory |
http://marc.info/?l=bugtraq&m=105839150004682&w=2 |
Configurations
Information
Published : 2003-08-17 21:00
Updated : 2016-10-17 19:35
NVD link : CVE-2003-0578
Mitre link : CVE-2003-0578
JSON object : View
CWE
Products Affected
ibm
- u2_universe