PT-2002-2593 · Sun · Sun Solaris
Published
2002-12-31
·
Updated
2018-10-30
·
CVE-2002-1871
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 2.5.1 through 8
Description
The issue allows attackers to elevate privileges by exploiting the
pkgadd installation process in Sun Solaris. This occurs when the pkgmap file contains a question mark in the mode, owner, or group fields, resulting in files being installed setuid/setgid root.Recommendations
For Sun Solaris versions 2.5.1 through 8, consider restricting the use of
pkgadd until a proper fix is applied, and ensure that pkgmap files are carefully validated to prevent the installation of files with elevated privileges.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris