CVE-2001-1555Improper Privilege Management in Solaris

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 79.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDsun/solaris8.0
NVDsun/sunos5.8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pqxf-cpww-63mq: pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other u2022-04-30
CVEList
CVE-2001-1555: pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other u2005-07-14

📐Framework References

1
CWE
Improper Privilege Management
CVE-2001-1555 — Improper Privilege Management | cvebase