Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.
Link | Tags |
---|---|
http://seer.support.veritas.com/tnotes/volumeman/230053.htm | |
http://www.securityfocus.com/bid/1356 | patch vendor advisory vdb entry exploit |
http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html | patch vendor advisory mailing list exploit |