PT-2001-2640 · Oracle · Solaris
Published
2001-12-31
·
Updated
2018-10-30
·
CVE-2001-1555
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Solaris version 8
Description
The issue concerns a problem with terminal privileges in Solaris 8. When users log out of terminals, the
pt chmod function does not properly reset terminal privileges by calling fdetach. This allows local users to write to other users' terminals by modifying the Access Control List (ACL) of a TTY.Recommendations
For Solaris 8, consider implementing a custom logout script that calls
fdetach to reset terminal privileges, or manually reset the ACL of the TTY after each logout to prevent unauthorized access.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solaris