Title: Cactus shell-lock Local Arbitrary Command Execution
Info
Disclosure
Oct 04, 1999
Discovery
Unknown
Dates
Exploit
Oct 04, 1999
Solution
Unknown
Description
Cactus International Software's shell-lock utility contains a flaw that allows local attackers to gain root privileges. The flaw is due to the program's handling of /tmp files in an insecure fashion. A local attacker can watch for the program to create a file, unlink the file and replace it with an arbitrary file, which will be executed with root privileges.
Classification
Unknown or Incomplete
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.