PT-1997-1242 · Oracle · Solaris Solstice Adminsuite
Published
1997-11-10
·
Updated
2008-09-05
·
CVE-1999-1427
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Solaris Solstice AdminSuite versions 2.1 through 2.2
Description
The issue allows local users to gain root privileges due to insecure creation of lock files.
Recommendations
For versions 2.1 and 2.2, consider restricting access to the lock file creation mechanism as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris Solstice Adminsuite