PT-2001-2640 · Oracle · Solaris

Published

2001-12-31

·

Updated

2018-10-30

·

CVE-2001-1555

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Solaris version 8
Description The issue concerns a problem with terminal privileges in Solaris 8. When users log out of terminals, the pt chmod function does not properly reset terminal privileges by calling fdetach. This allows local users to write to other users' terminals by modifying the Access Control List (ACL) of a TTY.
Recommendations For Solaris 8, consider implementing a custom logout script that calls fdetach to reset terminal privileges, or manually reset the ACL of the TTY after each logout to prevent unauthorized access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1555

Affected Products

Solaris