20020126 Vulnerability report for Tarantella Enterprise 3.mailing list
http://marc.info/?l=bugtraq&m=101208650722179&w=2 CVE-2002-0211
Tarantella Enterprise 3 - gunzip Race Condition
Record summary
CVE-2002-0211 has a selected CVSS score of 6.2; EIP currently links 1 catalogued exploit.
Description
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTarantella Enterprise 3 - gunzip Race ConditionExploitDB exploitby Larry CashdollarNot analyzed1 file
References
620020404 Exploit for Tarantella Enterprise 3 installation (BID 3966)mailing list
http://online.securityfocus.com/archive/1/265845 tarantella-gunzip-tmp-race(7996)vdb entry
http://www.iss.net/security_center/static/7996.php 3966vdb entry
http://www.securityfocus.com/bid/3966 tarantella.comConfirmation
http://www.tarantella.com/security/bulletin-04.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0211