Lucene search

K
cveMitreCVE-2001-1102
HistoryMar 15, 2002 - 5:00 a.m.

CVE-2001-1102

2002-03-1505:00:00
mitre
web.nvd.nist.gov
24
check point
firewall-1
solaris
file overwrite
local users
cpp extension
nvd

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0

Percentile

5.1%

Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.

Affected configurations

Nvd
Node
checkpointfirewall-1Match3.0
OR
checkpointfirewall-1Match4.0
OR
checkpointfirewall-1Match4.1
OR
checkpointfirewall-1Match4.1sp1
VendorProductVersionCPE
checkpointfirewall-13.0cpe:2.3:a:checkpoint:firewall-1:3.0:*:*:*:*:*:*:*
checkpointfirewall-14.0cpe:2.3:a:checkpoint:firewall-1:4.0:*:*:*:*:*:*:*
checkpointfirewall-14.1cpe:2.3:a:checkpoint:firewall-1:4.1:*:*:*:*:*:*:*
checkpointfirewall-14.1cpe:2.3:a:checkpoint:firewall-1:4.1:sp1:*:*:*:*:*:*

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2001-1102