« Volver al listado

CVE-2002-0211

Estado: ModificadaMedia (6.2)—

Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0211",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 1.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-05-16T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=101208650722179&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://online.securityfocus.com/archive/1/265845",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/7996.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/3966",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tarantella.com/security/bulletin-04.html",
      "tags": [
        "Patch",
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=101208650722179&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://online.securityfocus.com/archive/1/265845",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/7996.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/3966",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.tarantella.com/security/bulletin-04.html",
      "tags": [
        "Patch",
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary \"gunzip\" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed."
    },
    {
      "lang": "es",
      "value": "La condición de carrera en el script de instalación de Tarantella Enterprise 3 versiones 3.01 a 3.20 crea un programa temporal \"\"gunzip\"\" con permiso de escritura para todos los usuarios antes de ejecutarlo, lo cual podría permitir a usuarios locales la ejecución de comandos arbitrarios modificando el programa antes de que sea ejecutado."
    }
  ],
  "lastModified": "2026-06-16T21:57:00.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tarantella:tarantella_enterprise:3.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49253A0A-7DFA-4B92-9361-48B48F026E19"
            },
            {
              "criteria": "cpe:2.3:a:tarantella:tarantella_enterprise:3.3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D3D8C8E-7B2F-4543-8D00-1D25007012A1"
            },
            {
              "criteria": "cpe:2.3:a:tarantella:tarantella_enterprise:3.3.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93841F4A-16CB-4023-AE95-145036C6B898"
            },
            {
              "criteria": "cpe:2.3:a:tarantella:tarantella_enterprise:3.3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D3BC128-3AA6-4C87-A156-FDA71371BB42"
            },
            {
              "criteria": "cpe:2.3:a:tarantella:tarantella_enterprise:3.3.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EC5D9C1-8944-41C3-8810-6D42DEF4081E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}