CVE-2002-0296: Low severity Tarantella Tarantella Enterprise vulnerability
Published May 3, 2002
·Updated
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
Affected Software
5 affected components
Tarantella Tarantella Enterprise=3.0
Tarantella Tarantella Enterprise=3.01
Tarantella Tarantella Enterprise=3.10
Tarantella Tarantella Enterprise=3.11
Tarantella Tarantella Enterprise=3.20
Event History
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0296?
CVE-2002-0296 is considered a moderate severity vulnerability due to its potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2002-0296?
To fix CVE-2002-0296, upgrade Tarantella Enterprise to a version that addresses this vulnerability, such as versions 3.20 or higher.
3
Who is affected by CVE-2002-0296?
Local users of Tarantella Enterprise versions 3.0, 3.01, 3.10, 3.11, and 3.20 are affected by CVE-2002-0296.
4
What type of attack does CVE-2002-0296 represent?
CVE-2002-0296 represents a symlink attack that exploits temporary file handling in Tarantella Enterprise.
5
Is CVE-2002-0296 an example of a local or remote vulnerability?
CVE-2002-0296 is an example of a local vulnerability, as it requires local access to exploit.