PT-2007-4963 · Sun · Sun Solaris
Published
2007-07-12
·
Updated
2018-10-30
·
CVE-2007-3717
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8, 9, and 10 before 20070710
Description
The issue is related to the rcp command on Sun Solaris, which does not properly call certain helper applications. This allows local users to gain privileges by creating files with specific names, possibly containing shell metacharacters or spaces.
Recommendations
For Sun Solaris versions 8, 9, and 10 before 20070710, update to a version released after 20070710 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris