Vulnerability Name: | CVE-2003-1575 (CCN-12452) | ||||||||
Assigned: | 2003-05-30 | ||||||||
Published: | 2003-05-30 | ||||||||
Updated: | 2010-01-31 | ||||||||
Summary: | VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2003-1575 Source: CCN Type: Veritas TechNote ID: 258837 VERITAS File System 3.4 Patch 4 Rolling Patch 3 is now available Source: CCN Type: Sun Alert ID: 55060 Access Control List (ACL) Permissions May Not be Consistently Set on New VERITAS File System (VxFS) Files Which May Allow Unauthorized Access Source: CONFIRM Type: Patch http://sunsolve.sun.com/search/document.do?assetkey=1-21-113207-05-1 Source: SUNALERT Type: Patch, Vendor Advisory 200161 Source: CCN Type: OSVDB ID: 19041 VERITAS File System (VxFS) Unspecified Local File Restriction Bypass Source: CCN Type: BID-8053 Sun Solaris Veritas File System Unauthorized Information Access Vulnerability Source: XF Type: UNKNOWN veritas-filesystem-acl-permissions(12452) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
BACK |