CVE-2002-0246: High severity Caldera UnixWare vulnerability
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LCMESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0246?
CVE-2002-0246 has a moderate severity rating due to the potential for local privilege escalation.
How do I fix CVE-2002-0246?
To fix CVE-2002-0246, ensure that the LC_MESSAGE environment variable is not modified by unprivileged users.
Who is affected by CVE-2002-0246?
CVE-2002-0246 primarily affects users of UnixWare 7.1.1 due to the inherent vulnerabilities in its message catalog library functions.
Can CVE-2002-0246 be exploited remotely?
CVE-2002-0246 requires local access to the system, making it a local exploitation vulnerability rather than a remote one.
What types of attacks are possible with CVE-2002-0246?
Exploitation of CVE-2002-0246 can allow a local user to execute arbitrary code with elevated privileges.