PT-2005-1115 · Oracle · Kcms+1

Published

2005-02-23

·

Updated

2018-10-30

·

CVE-2004-0481

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions KCMS package versions on Solaris 8 and 9
Description The logging feature in kcms configure has an issue that allows local users to corrupt arbitrary files via a symlink attack on the KCS ClogFile file.
Recommendations For KCMS package versions on Solaris 8 and 9, consider restricting access to the logging feature in kcms configure to prevent arbitrary file corruption until a fix is available. As a temporary workaround, consider disabling the logging feature in kcms configure to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0481

Affected Products

Kcms
Solaris