CVE-2002-0677

UnknownEPSS 6.57%

Last modified

CVE-2002-0677 is a vulnerability of currently unknown severity. CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.. EPSS estimates a 6.57% chance of exploitation in the next 30 days.

Description

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

Metrics

CVSS 3.0
/10
EPSS Probability
6.57%

93.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CalderaUnixware7
CalderaUnixware7.1.1
CalderaUnixware7.1_.0
Xi GraphicsDextop2.1
SgiIrix5.2
SgiIrix5.3
SgiIrix6.0
SgiIrix6.0.1
SgiIrix6.1
SgiIrix6.2
SgiIrix6.3
SgiIrix6.4
SgiIrix6.5
SgiIrix6.5.1
SgiIrix6.5.2
SgiIrix6.5.3
SgiIrix6.5.4
SgiIrix6.5.5
SgiIrix6.5.6
SgiIrix6.5.7
SgiIrix6.5.8
SgiIrix6.5.9
SgiIrix6.5.10
SgiIrix6.5.11
SgiIrix6.5.12
SgiIrix6.5.13
SgiIrix6.5.14
SgiIrix6.5.15
SgiIrix6.5.16
CalderaOpenunix8.0
CompaqTru644.0f
CompaqTru644.0g
CompaqTru645.0a
CompaqTru645.1
CompaqTru645.1a
HpHp-Ux10.10
HpHp-Ux10.20
HpHp-Ux10.24
HpHp-Ux11.00
HpHp-Ux11.11
IbmAix4.3.3
IbmAix5.1
SunSolaris2.6
SunSunos5.5.1
SunSunos5.7
SunSunos5.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2002-0677?
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
How severe is CVE-2002-0677?
Severity scoring for CVE-2002-0677 is pending analysis. The EPSS model estimates a 6.57% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0677?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2002-0677?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST