First published: Fri May 03 2002(Updated: )
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Tarantella Enterprise | =3.0 | |
Oracle Tarantella Enterprise | =3.01 | |
Oracle Tarantella Enterprise | =3.10 | |
Oracle Tarantella Enterprise | =3.11 | |
Oracle Tarantella Enterprise | =3.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0296 is considered a moderate severity vulnerability due to its potential for local users to overwrite arbitrary files.
To fix CVE-2002-0296, upgrade Tarantella Enterprise to a version that addresses this vulnerability, such as versions 3.20 or higher.
Local users of Tarantella Enterprise versions 3.0, 3.01, 3.10, 3.11, and 3.20 are affected by CVE-2002-0296.
CVE-2002-0296 represents a symlink attack that exploits temporary file handling in Tarantella Enterprise.
CVE-2002-0296 is an example of a local vulnerability, as it requires local access to exploit.