First published: Fri Oct 04 2002(Updated: )
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xinuos OpenServer | =5.0.5 | |
Xinuos OpenServer | =5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0887 has a medium severity rating as it allows local users to overwrite arbitrary files.
To fix CVE-2002-0887, ensure that temporary files used by scoadmin are protected against symlink attacks.
CVE-2002-0887 affects users of Caldera/SCO OpenServer versions 5.0.5 and 5.0.6.
A symlink attack in CVE-2002-0887 involves exploiting temporary file handling to overwrite files by creating symbolic links.
No, CVE-2002-0887 can only be exploited by local users with access to the affected system.