PT-2002-2593 · Sun · Sun Solaris

Published

2002-12-31

·

Updated

2018-10-30

·

CVE-2002-1871

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 2.5.1 through 8
Description The issue allows attackers to elevate privileges by exploiting the pkgadd installation process in Sun Solaris. This occurs when the pkgmap file contains a question mark in the mode, owner, or group fields, resulting in files being installed setuid/setgid root.
Recommendations For Sun Solaris versions 2.5.1 through 8, consider restricting the use of pkgadd until a proper fix is applied, and ensure that pkgmap files are carefully validated to prevent the installation of files with elevated privileges.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1871

Affected Products

Sun Solaris