CVE-2008-0310: Path Traversal
Published Apr 7, 2008
·Updated
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.
Affected Software
1 affected component
SCO UnixWare=7.1.4
Remediation
Event History
Apr 7, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0310?
CVE-2008-0310 is classified as a medium severity vulnerability.
2
How do I fix CVE-2008-0310?
To mitigate CVE-2008-0310, apply the security patch provided by SCO for UnixWare 7.1.4.
3
Who is affected by CVE-2008-0310?
Local users of SCO UnixWare 7.1.4 prior to patch p534589 are affected by CVE-2008-0310.
4
What type of vulnerability is CVE-2008-0310?
CVE-2008-0310 is a directory traversal vulnerability.
5
What can attackers do with CVE-2008-0310?
Attackers can exploit CVE-2008-0310 to create or append to arbitrary files on the system.