PT-2002-3035 · Sun · Sun Pc Netlink
Published
2002-12-31
·
Updated
2024-01-25
·
CVE-2002-2323
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun PC NetLink versions 1.0 through 1.2
Description
The issue is related to the improper setting of the access control list (ACL) for files and directories that use symbolic links and have been restored from backup. This could allow local or remote attackers to bypass intended access restrictions.
Recommendations
For Sun PC NetLink versions 1.0 through 1.2, consider restricting access to files and directories that use symbolic links until a proper fix is applied to ensure the correct setting of ACLs. As a temporary workaround, review and manually set the ACLs for affected files and directories to prevent unauthorized access.
Fix
Link Following
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Pc Netlink