Vulnerabilities > CVE-2002-0246 - Unspecified vulnerability in Caldera Unixware 7.1.1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
caldera
exploit available

Summary

Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.

Vulnerable Configurations

Part Description Count
Application
Caldera
1

Exploit-Db

descriptionCaldera UnixWare 7.1.1 Message Catalog Environment Variable Format String Vulnerability. CVE-2002-0246. Local exploit for unixware platform
idEDB-ID:21284
last seen2016-02-02
modified2002-02-07
published2002-02-07
reporterjGgM
sourcehttps://www.exploit-db.com/download/21284/
titleCaldera UnixWare 7.1.1 Message Catalog Environment Variable Format String Vulnerability