20020925 Borland Interbase local root exploitmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-09/0311.html CVE-2002-1514
Interbase 5/6 - GDS_Lock_MGR UMask File Permission Changing
Record summary
CVE-2002-1514 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBInterbase 5/6 - GDS_Lock_MGR UMask File Permission ChangingExploitDB exploitby grazerNot analyzed1 file
References
4interbase-gdslockmgr-bo(10196)vdb entry
http://www.iss.net/security_center/static/10196.php 5805vdb entry
http://www.securityfocus.com/bid/5805 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1514