CVE-2000-0224: Low severity SCO UnixWare vulnerability
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ARCserve agent (SCO UnixWare 7.x)from your environment.Uninstall the ARCserve agent from SCO UnixWare 7.x systems if it is not required. The agent is vulnerable to a local symlink attack that can allow privilege escalation to root.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0224?
CVE-2000-0224 is considered a high severity vulnerability due to its potential to allow local attackers to gain root privileges.
How do I fix CVE-2000-0224?
To mitigate CVE-2000-0224, ensure that the ARCserve agent is upgraded to a version that is not vulnerable to symlink attacks.
Who is affected by CVE-2000-0224?
CVE-2000-0224 affects users of SCO UnixWare versions 7.1 and 7.1.1 that have the ARCserve agent installed.
Can CVE-2000-0224 be exploited remotely?
CVE-2000-0224 cannot be exploited remotely as it requires local access to the system.
What type of attack is associated with CVE-2000-0224?
CVE-2000-0224 is associated with a symlink attack that can be used to elevate privileges.