First published: Wed Apr 02 2003(Updated: )
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
InterBase | =4.0 | |
InterBase | =5.0 | |
InterBase | =6.0 | |
InterBase | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1514 is considered a high severity vulnerability due to its ability to allow local users to gain elevated privileges through a symlink attack.
To fix CVE-2002-1514, ensure that the software is updated to a patched version that eliminates the vulnerability.
CVE-2002-1514 affects Borland InterBase versions 4.0, 5.0, 6.0, and 6.5.
CVE-2002-1514 can be exploited through symlink attacks, allowing local users to overwrite files and escalate privileges.
A potential workaround for CVE-2002-1514 is to restrict access to the affected temporary files to prevent unauthorized local users from performing the symlink attack.