Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-0211. PoCs published by Larry Cashdollar.
AI-analyzed exploit summary This exploit targets a race condition in Tarantella Enterprise 3 installation, where a root-owned binary in /tmp can be overwritten by a local user. The script continuously monitors for the creation of the vulnerable binary and replaces it with a malicious script to gain root privileges.
Description
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
Exploits (1)
This exploit targets a race condition in Tarantella Enterprise 3 installation, where a root-owned binary in /tmp can be overwritten by a local user. The script continuously monitors for the creation of the vulnerable binary and replaces it with a malicious script to gain root privileges.