Description
pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-967-1 | New elog packages fix arbitrary code execution |
EUVD |
EUVD-2006-4427 | pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T19:06:07.668Z
Reserved: 2006-08-29T00:00:00.000Z
Link: CVE-2006-4439
No data.
Status : Modified
Published: 2006-08-29T23:04:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-4439
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD