PT-2003-2015 · Sun · Xsun
Published
2003-12-03
·
Updated
2018-10-30
·
CVE-2003-1058
CVSS v2.0
3.7
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xsun server for Sun Solaris versions 2.6 through 9
Description
The issue allows local users to cause a denial of service, resulting in an Xsun crash, or to create or overwrite arbitrary files on the system. This is likely achieved via a symlink attack on temporary server files when the Xsun server is running in Direct Graphics Access (DGA) mode.
Recommendations
For Xsun server for Sun Solaris versions 2.6 through 9, consider disabling the DGA mode as a temporary workaround to minimize the risk of exploitation. Restrict access to temporary server files to prevent symlink attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xsun