cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
References
| Link | Resource |
|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html | Broken Link Exploit Vendor Advisory |
| http://marc.info/?l=bugtraq&m=105839150004682&w=2 | Mailing List |
| http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html | Broken Link Exploit Vendor Advisory |
| http://marc.info/?l=bugtraq&m=105839150004682&w=2 | Mailing List |
Configurations
History
No history.
Information
Published : 2003-08-18 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2003-0578
Mitre link : CVE-2003-0578
CVE.ORG link : CVE-2003-0578
JSON object : View
Products Affected
ibm
- u2_universe
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
