PT-2005-1115 · Oracle · Kcms+1

Publicado

2005-02-23

·

Atualizado

2018-10-30

·

CVE-2004-0481

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions KCMS package versions on Solaris 8 and 9
Description The logging feature in kcms configure has an issue that allows local users to corrupt arbitrary files via a symlink attack on the KCS ClogFile file.
Recommendations For KCMS package versions on Solaris 8 and 9, consider restricting access to the logging feature in kcms configure to prevent arbitrary file corruption until a fix is available. As a temporary workaround, consider disabling the logging feature in kcms configure to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0481

Produtos afetados

Kcms
Solaris