Vulnerability Name: | CVE-2002-2323 (CCN-9665) | ||||||||
Assigned: | 2002-07-15 | ||||||||
Published: | 2002-07-15 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-59 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-2323 Source: CCN Type: Sun Alert ID: 27807 PC Netlink's Access Control List Permissions May be Lost After Restore of a Backup Source: SUNALERT Type: UNKNOWN 27807 Source: XF Type: UNKNOWN sun-pcnetlink-acl-permissions(9665) Source: CCN Type: OSVDB ID: 60241 Sun PC NetLink Backup Restored Symlink ACL Application Restriction Bypass Source: BID Type: UNKNOWN 5281 Source: CCN Type: BID-5281 Sun PC NetLink Backup Restoration ACL Permissions Vulnerability Source: CCN Type: Sun Microsystems, Inc. Web site SOLARIS PC NETLINK SOFTWARE Source: XF Type: UNKNOWN sun-pcnetlink-acl-permissions(9665) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |