CVE-2002-0677

Publication date

2002-07-12 04:00:00

Family

mitre

State

PUBLISHED

Description

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.