7.2

CVE-2002-0246

Exploit
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Caldera ≫ Unixware Version 7.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.574
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://stage.caldera.com/pub/security/unixware/CSSA-2002-SCO.3/CSSA-2002-SCO.3.txt
Patch
Vendor Advisory
http://online.securityfocus.com/archive/1/255414
Vendor Advisory
Exploit
http://www.iss.net/security_center/static/8113.php
Patch
Vendor Advisory
http://www.securityfocus.com/bid/4060