Vulnerabilities > CVE-2000-0494 - Unspecified vulnerability in Symantec Veritas Volume Manager 3.0.2/3.0.3/3.0.4

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
symantec-veritas
exploit available

Summary

Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.

Exploit-Db

descriptionVeritas Software Volume Manager 3.0.2/3.0.3/3.0.4 File Permission Vulnerability. CVE-2000-0494. Local exploit for solaris platform
idEDB-ID:20018
last seen2016-02-02
modified2000-06-16
published2000-06-16
reporterDixie Flatline
sourcehttps://www.exploit-db.com/download/20018/
titleVeritas Software Volume Manager 3.0.2/3.0.3/3.0.4 File Permission Vulnerability