Vulnerability Name: | CVE-2003-1081 (CCN-10105) | ||||||||
Assigned: | 2002-09-11 | ||||||||
Published: | 2002-09-11 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2003-1081 Source: CCN Type: Sun Alert ID: 46903 aspppls(1M) Does Not Create the Temporary File /tmp/.asppp.fifo Safely Source: SUNALERT Type: Exploit, Patch, Vendor Advisory 46903 Source: AUSCERT Type: Vendor Advisory ESB-2003.0621 Source: CCN Type: CIAC Information Bulletin O-001 Sun aspppls(1M) does not create the temporary file /tmp/.asppp.fifo safely Source: CIAC Type: Vendor Advisory O-001 Source: CCN Type: US-CERT VU#464817 Sun Solaris asppls(1M) vulnerable to arbitrary file overwriting via symlink redirection of temporary file Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#464817 Source: CCN Type: OSVDB ID: 15139 Solaris Aspppls .asppp.fifo Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 5698 Source: CCN Type: BID-5698 Sun Solaris ASPPPLS Insecure Temporary File Creation Vulnerability Source: CCN Type: BID-570 Multiple Vendor profil(2) Vulnerability Source: XF Type: UNKNOWN solaris-aspppls-tmpfile-symlink(10105) Source: XF Type: UNKNOWN solaris-aspppls-tmpfile-symlink(10105) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |