Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0211

EPSS 0.32% · P55
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-0211

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tarantella Enterprise 3 gunzip竞争条件漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tarantella Enterprise 3是一个基于Web的集中化的IT应用环境控制软件。 Tarantella Enterprise在安装过程中存在竞争条件问题,可以使本地攻击者得到主机的root权限。 在安装过程中,程序会在$TMPDIR环境变量指定的临时文件目录(通常是/tmp)中创建一个二进制的gunzip文件,此文件的文件名一般是gunzip$$,$$代表了进程号,安装程序会以root身份在以后的安装过程中用到这个gunzip程序。这个gunzip程序在被创建时是全局可读写的,如果能在它被使
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-0211

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-0211

Please Login to view more intelligence information

Same Patch Batch · n/a · 2002-06-25 · 190 CVEs total

CVE-2002-0027Microsoft Internet Explorer安全漏洞
CVE-2002-0002STunnel客户端协商协议格式串溢出漏洞
CVE-2002-0003Groff预处理器缓冲区溢出漏洞
CVE-2002-0004AT 畸形时间格式导致堆溢出漏洞
CVE-2002-0007BugZilla LDAP认证绕过漏洞
CVE-2002-0018Microsoft Windows网络域间信任关系提升权限漏洞(MS02-001)
CVE-2002-0020Microsoft Telnet Server协议选项缓冲溢出漏洞(MS02-004)
CVE-2002-0021Macintosh Microsoft Office v. X Network PID检查器服务拒绝漏洞
CVE-2002-0022Microsoft Internet Explorer安全漏洞
CVE-2002-0023Microsoft Internet Explorer安全漏洞
CVE-2002-0025Microsoft Internet Explorer安全漏洞
CVE-2002-0026Microsoft Internet Explorer安全漏洞
CVE-2002-0045OpenLDAP认证用户目标属性缺失漏洞
CVE-2002-0051Microsoft Windows 2000组策略锁定漏洞(MS02-016)
CVE-2002-0050Microsoft Commerce Server ISAPI远程缓冲区溢出漏洞(MS02-033)
CVE-2002-0049Microsoft Exchange Server 安全漏洞
CVE-2002-0047CIPE VPN数据包服务拒绝漏洞
CVE-2002-0046Linux kernel内存信息泄露漏洞
CVE-2002-0040SGI IRIX HOSTALIASES拒绝服务攻击漏洞
CVE-2002-0028ICQ缓冲区溢出漏洞

Showing top 20 of 190 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-0211

No comments yet


Leave a comment