Vulnerabilities > CVE-2002-0678 - Symbolic Link vulnerability in Multiple Vendor CDE ToolTalk Database Server

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE

Summary

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

Oval

  • accepted2010-09-20T04:00:17.387-04:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameTodd Dolinsky
      organizationOpsware, Inc.
    • nameJonathan Baker
      organizationThe MITRE Corporation
    descriptionCDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
    familyunix
    idoval:org.mitre.oval:def:175
    statusaccepted
    submitted2003-01-29T12:00:00.000-04:00
    titleSolaris 8 CDE ToolTalk Database Server Symbolic Link Vulnerability
    version37
  • accepted2010-09-20T04:00:20.686-04:00
    classvulnerability
    contributors
    • nameBrian Soby
      organizationThe MITRE Corporation
    • nameBrian Soby
      organizationThe MITRE Corporation
    • nameBrian Soby
      organizationThe MITRE Corporation
    • nameTodd Dolinsky
      organizationOpsware, Inc.
    • nameJonathan Baker
      organizationThe MITRE Corporation
    descriptionCDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
    familyunix
    idoval:org.mitre.oval:def:2770
    statusaccepted
    submitted2004-10-15T12:00:00.000-04:00
    titleSolaris 9 CDE ToolTalk Database Server Symbolic Link Vulnerability
    version39
  • accepted2010-09-20T04:00:37.114-04:00
    classvulnerability
    contributors
    • nameDavid Proulx
      organizationThe MITRE Corporation
    • nameTodd Dolinsky
      organizationOpsware, Inc.
    • nameJonathan Baker
      organizationThe MITRE Corporation
    descriptionCDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
    familyunix
    idoval:org.mitre.oval:def:80
    statusaccepted
    submitted2003-01-29T12:00:00.000-04:00
    titleSolaris 7 CDE ToolTalk Database Symbolic Link Vulnerability
    version37