First published: Mon Oct 28 2002(Updated: )
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SCO OpenLinux Server | =2.4 | |
SCO OpenLinux Server | =2.2 | |
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Xinuos OpenServer | =5.0.5 | |
Oracle Solaris and Zettabyte File System (ZFS) | =9.0 | |
Xinuos OpenServer | =5.0.6a | |
Xinuos OpenServer | =5.0.6 | |
SCO OpenLinux Server | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1199 is considered a medium severity vulnerability due to its potential for local and remote exploitation.
To fix CVE-2002-1199, ensure that your system is updated to the latest version provided by the vendor or apply any available patches.
CVE-2002-1199 affects various versions of SCO OpenLinux, Xinuos OpenServer, and Sun Solaris.
Yes, CVE-2002-1199 can be exploited by remote attackers to read databases outside of the intended directory.
CVE-2002-1199 involves a directory traversal and symlink attack vulnerability.