First published: Fri Jun 16 2000(Updated: )
Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas Volume Manager | =3.0.2 | |
Symantec Veritas Volume Manager | =3.0.3 | |
Symantec Veritas Volume Manager | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0494 has a high severity level due to the potential for local users to execute arbitrary commands.
To fix CVE-2000-0494, ensure that the .server_pids file is not world writable by changing its permissions.
CVE-2000-0494 affects Symantec Veritas Volume Manager versions 3.0.2, 3.0.3, and 3.0.4.
CVE-2000-0494 is a local file permission vulnerability that allows for command injection.
CVE-2000-0494 cannot be exploited remotely as it requires local access to the system.