[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0823Date: (C)2001-12-06   (M)2023-12-22


The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
20010601-01-A
http://marc.info/?l=bugtraq&m=99290754901708&w=2
http://archives.neohapsis.com/archives/bugtraq/2001-06/0245.html
BID-2887
irix-pcp-pmpost-symlink(6724)

CPE    12
cpe:/a:sgi:performance_co-pilot:2.1.9
cpe:/a:sgi:performance_co-pilot:2.1.8
cpe:/a:sgi:performance_co-pilot:2.1.7
cpe:/a:sgi:performance_co-pilot:2.1.6
...

© SecPod Technologies