Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
2002-05-16T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 6.2 (MEDIUM)
AV:L/AC:H/Au:N/C:C/I:C/A:C
1.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tarantella | tarantella_enterprise | 3.3.0 | Yes |
Application | tarantella | tarantella_enterprise | 3.3.0.1 | Yes |
Application | tarantella | tarantella_enterprise | 3.3.10 | Yes |
Application | tarantella | tarantella_enterprise | 3.3.11 | Yes |
Application | tarantella | tarantella_enterprise | 3.3.20 | Yes |