CVE-2002-1871
published 2002-12-31CVE-2002-1871: pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3)…
PriorityP416high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.35%
27.6th percentile
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r8w2-jqrm-hxg6: pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (q
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2006-4439 [HIGH] GHSA-r8w2-jqrm-hxg6: pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (q
pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
GHSA
GHSA-gjh3-jcfj-99r5: pkgadd in Sun Solaris 2
ghsa_unreviewed·2022-04-30
CVE-2002-1871 [HIGH] GHSA-gjh3-jcfj-99r5: pkgadd in Sun Solaris 2
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-45693-1http://www.iss.net/security_center/static/9544.phphttp://www.securityfocus.com/bid/5208http://sunsolve.sun.com/search/document.do?assetkey=1-26-45693-1http://www.iss.net/security_center/static/9544.phphttp://www.securityfocus.com/bid/5208
2002-12-31
Published