CVE-2002-0887: Low severity Caldera OpenServer vulnerability
Published Oct 4, 2002
·Updated
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.
Affected Software
2 affected components
Caldera OpenServer=5.0.5
Caldera OpenServer=5.0.6
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0887?
CVE-2002-0887 has a medium severity rating as it allows local users to overwrite arbitrary files.
2
How do I fix CVE-2002-0887?
To fix CVE-2002-0887, ensure that temporary files used by scoadmin are protected against symlink attacks.
3
Who is affected by CVE-2002-0887?
CVE-2002-0887 affects users of Caldera/SCO OpenServer versions 5.0.5 and 5.0.6.
4
What is a symlink attack in the context of CVE-2002-0887?
A symlink attack in CVE-2002-0887 involves exploiting temporary file handling to overwrite files by creating symbolic links.
5
Can remote users exploit CVE-2002-0887?
No, CVE-2002-0887 can only be exploited by local users with access to the affected system.