PT-2010-1195 · Sun+1 · Sun Solaris+1
Publicado
2010-01-28
·
Atualizado
2010-01-31
·
CVE-2003-1575
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VERITAS File System (VxFS) versions 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9
Description
The issue is related to the improper implementation of inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode. This allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.
Recommendations
For VERITAS File System (VxFS) versions 3.3.3, 3.4, and 3.5, apply MP1 Rolling Patch 02 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sun Solaris
Veritas File System