Back to Database
Status published
Medium
CVE-2008-0310
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before...
Vulnerability Description
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0310
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.sco.com/support/update/download/release.php?rid=324
- http://www.securitytracker.com/id?1019787
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41759
- http://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.txt
- https://www.exploit-db.com/exploits/5355
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=676
- http://secunia.com/advisories/29657
More from sco
View All →CVE-2011-1432
The STARTTLS implementation in SCO SCOoffice Server does not properly...
Medium
6.8
CVE-2009-1552
Unspecified vulnerability in the IGMP driver in SCO Unixware Release...
High
7.8
CVE-2008-6559
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows...
High
7.2
CVE-2008-6558
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm...
High
7.2
CVE-2008-1343
Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in...
Medium
4.9
Affected Vendor
Affected Software
unixware
Vulnerable Versions:
7.1.4
Timeline
Official Publish:
April 7th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.