Vulnerability Description
Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Arcserve Backup | 6.61 |
| Ca | Arcserve Backup | 6.63 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0184.html
- http://www.securityfocus.com/bid/2741
- http://www.securityfocus.com/bid/2748
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0184.html
- http://www.securityfocus.com/bid/2741
- http://www.securityfocus.com/bid/2748
FAQ
What is CVE-2001-1346?
CVE-2001-1346 is a vulnerability with a CVSS score of 1.2 (LOW). Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.
How severe is CVE-2001-1346?
CVE-2001-1346 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1346?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Arcserve Backup, Ca Arcserve Backup.