HIGH · 7.5

CVE-2002-0677

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX proc...

Vulnerability Description

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CalderaUnixware7
Xi GraphicsDextop2.1
SgiIrix5.2
CalderaOpenunix8.0
CompaqTru644.0f
HpHp-Ux10.10
IbmAix4.3.3
SunSolaris2.6
SunSunos5.5.1

References

FAQ

What is CVE-2002-0677?

CVE-2002-0677 is a vulnerability with a CVSS score of 7.5 (HIGH). CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX proc...

How severe is CVE-2002-0677?

CVE-2002-0677 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0677?

Check the references section above for vendor advisories and patch information. Affected products include: Caldera Unixware, Xi Graphics Dextop, Sgi Irix, Caldera Openunix, Compaq Tru64.