Back to Database
Status published
High
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite...
Vulnerability Description
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-0678
Credits & Attribution
No credits recorded in the NVD database.
References
- ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.28/CSSA-2002-SCO.28.txt
- http://www.cert.org/advisories/CA-2002-20.html
- http://marc.info/?l=bugtraq&m=102635906423617&w=2
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0207-199
- http://archives.neohapsis.com/archives/aix/2002-q3/0002.html
- http://archives.neohapsis.com/archives/aix/2002-q3/0002.html
- http://www.kb.cert.org/vuls/id/299816
- ftp://patches.sgi.com/support/free/security/advisories/20021101-01-P
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A175
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A80
- http://www.securityfocus.com/bid/5083
- http://www.iss.net/security_center/static/9527.php
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2770
More from caldera
View All →CVE-2014-2936
The directory manager in Caldera 9.20 allows remote attackers to...
High
7.5
CVE-2014-2935
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to...
Critical
10
CVE-2014-2934
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers...
High
7.5
CVE-2014-2933
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote...
Medium
5
CVE-2003-0658
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0,...
Medium
5
Affected Vendor
caldera
View all reports →Affected Software
unixware, dextop, irix, openunix, tru64, hp-ux, aix, solaris, sunos
Vulnerable Versions:
7.0, 7.1.0, 7.1.1, 2.1, 5.2, 5.3, 6.0, 6.0.1, 6.1, 6.2, 6.3, 6.4, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.5.11, 6.5.12, 6.5.13, 6.5.14, 6.5.15, 6.5.16, 8.0, 4.0f, 4.0g, 5.0a, 5.1, 5.1a, 10.10, 10.20, 10.24, 11.00, 11.11, 4.3.3, 2.6, 9.0, 5.5.1, 5.7, 5.8
Timeline
Official Publish:
April 2nd, 2003
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.