Vulnerabilities > CVE-2000-0494 - Unspecified vulnerability in Symantec Veritas Volume Manager 3.0.2/3.0.3/3.0.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN symantec-veritas
exploit available
Summary
Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Veritas Software Volume Manager 3.0.2/3.0.3/3.0.4 File Permission Vulnerability. CVE-2000-0494. Local exploit for solaris platform |
id | EDB-ID:20018 |
last seen | 2016-02-02 |
modified | 2000-06-16 |
published | 2000-06-16 |
reporter | Dixie Flatline |
source | https://www.exploit-db.com/download/20018/ |
title | Veritas Software Volume Manager 3.0.2/3.0.3/3.0.4 File Permission Vulnerability |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html
- http://seer.support.veritas.com/tnotes/volumeman/230053.htm
- http://seer.support.veritas.com/tnotes/volumeman/230053.htm
- http://www.securityfocus.com/bid/1356
- http://www.securityfocus.com/bid/1356