CVE-2000-0494: High severity Symantec Veritas Volume Manager vulnerability
Published Jun 16, 2000
·Updated
Veritas Volume Manager creates a world writable .serverpids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsaserver script.
Affected Software
3 affected components
Symantec Veritas Volume Manager=3.0.2
Symantec Veritas Volume Manager=3.0.3
Symantec Veritas Volume Manager=3.0.4
Remediation
Patch Available
Event History
Jun 16, 2000
CVE Published
04:00 AM
Oct 13, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0494?
CVE-2000-0494 has a high severity level due to the potential for local users to execute arbitrary commands.
2
How do I fix CVE-2000-0494?
To fix CVE-2000-0494, ensure that the .server_pids file is not world writable by changing its permissions.
3
Which versions of Veritas Volume Manager are affected by CVE-2000-0494?
CVE-2000-0494 affects Symantec Veritas Volume Manager versions 3.0.2, 3.0.3, and 3.0.4.
4
What type of vulnerability is CVE-2000-0494?
CVE-2000-0494 is a local file permission vulnerability that allows for command injection.
5
Can CVE-2000-0494 be exploited remotely?
CVE-2000-0494 cannot be exploited remotely as it requires local access to the system.