Vulnerability Name: | CVE-2003-1073 (CCN-11180) | ||||||||
Assigned: | 2003-01-27 | ||||||||
Published: | 2003-01-27 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place. | ||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: VulnWatch Mailing List, Mon Jan 27 2003 - 06:06:21 CST Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities Source: VULNWATCH Type: UNKNOWN 20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities Source: MITRE Type: CNA CVE-2003-1073 Source: MISC Type: UNKNOWN http://isec.pl/vulnerabilities/isec-0008-sun-at.txt Source: CCN Type: SA7960 Solaris arbitrary file deletion Source: SECUNIA Type: Patch 7960 Source: CCN Type: SECTRACK ID: 1005994 Sun Solaris `at` Command Race Condition Enables Local Users to Delete Arbitrary Files Source: CCN Type: Sun Alert ID: 50161 Security Vulnerability with the at(1) Command on Solaris Source: SUNALERT Type: Vendor Advisory 50161 Source: CCN Type: CIAC Information Bulletin N-070 Sun Solaris at(1) Command Vulnerability Source: CIAC Type: UNKNOWN N-070 Source: CCN Type: OSVDB ID: 15142 Solaris at -r Argument Race Condition Arbitrary File Deletion Source: BUGTRAQ Type: UNKNOWN 20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities Source: BID Type: UNKNOWN 6692 Source: CCN Type: BID-6692 Sun Solaris AT Command Arbitrary File Deletion Vulnerability Source: BID Type: UNKNOWN 6693 Source: CCN Type: BID-6693 Sun Solaris AT Command Race Condition Vulnerability Source: SECTRACK Type: UNKNOWN 1005994 Source: XF Type: UNKNOWN solaris-at-directory-traversal(11179) Source: XF Type: UNKNOWN solaris-at-race-condition(11180) Source: XF Type: UNKNOWN solaris-at-race-condition(11180) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |