cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html | Broken Link Exploit Vendor Advisory |
http://marc.info/?l=bugtraq&m=105839150004682&w=2 | Mailing List |
Configurations
History
No history.
Information
Published : 2003-08-18 04:00
Updated : 2024-01-26 17:19
NVD link : CVE-2003-0578
Mitre link : CVE-2003-0578
CVE.ORG link : CVE-2003-0578
JSON object : View
Products Affected
ibm
- u2_universe
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')