Lucene search

K
cveMitreCVE-2001-1346
HistoryMay 03, 2002 - 4:00 a.m.

CVE-2001-1346

2002-05-0304:00:00
mitre
web.nvd.nist.gov
22
cve-2001-1346
arcserveit
symlink attack
overwrite arbitrary files
temporary files
asagent.tmp
inetd.tmp.

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

30.2%

Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

Affected configurations

Nvd
Node
broadcomarcserve_backupMatch6.61
OR
caarcserve_backupMatch6.63
VendorProductVersionCPE
broadcomarcserve_backup6.61cpe:2.3:a:broadcom:arcserve_backup:6.61:*:*:*:*:*:*:*
caarcserve_backup6.63cpe:2.3:a:ca:arcserve_backup:6.63:*:*:*:*:*:*:*

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

30.2%

Related for CVE-2001-1346