20000616 Veritas Volume Manager 3.0.x holemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html CVE-2000-0494
Veritas Software Volume Manager 3.0.2/3.0.3/3.0.4 - File Permission
Record summary
CVE-2000-0494 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVeritas Software Volume Manager 3.0.2/3.0.3/3.0.4 - File PermissionExploitDB exploitby Dixie FlatlineNot analyzed1 file
References
4seer.support.veritas.comConfirmation
http://seer.support.veritas.com/tnotes/volumeman/230053.htm 1356vdb entry
http://www.securityfocus.com/bid/1356 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0494