CVE-2003-1063
published 2003-08-20CVE-2003-1063: The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently…
PriorityP425high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.54%
72.1th percentile
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Heap Overflow in Solaris cachefs Daemon
vendor_cisco·2002-07-24
CVE-2002-0033 CWE-119 Heap Overflow in Solaris cachefs Daemon
Heap Overflow in Solaris cachefs Daemon
This advisory describes a vulnerability that affects Cisco products and
applications that are installed on the Solaris operating system, and is based
on the vulnerability of an common service within the Solaris operating system,
not due to a defect of the Cisco product or application. A vulnerability in the
"cachefs" program was discovered that enables an attacker to execute arbitrary
code under Solaris OS. This vulnerability was publicly announced in the CERT
Advisory CA-2002-11. All Cisco products and applications that are installed on
Solaris OS are considered vulnerable to the underlying operating system
vulnerability, unless the workaround was applied. This vulnerability is
described in details in Sun(sm) Alert Notification at
http://sunsolve
Cisco
Heap Overflow in Solaris cachefs Daemon
vendor_cisco
CVE-2003-1063 Heap Overflow in Solaris cachefs Daemon
CVE-2003-1063: Heap Overflow in Solaris cachefs Daemon
This advisory describes a vulnerability that affects Cisco products and applications that are installed on the Solaris operating system, and is based on the vulnerability of an common service within the Solaris operating system, not due to a defect of the Cisco product or application. A vulnerability in the "cachefs" program was discovered that enables an attacker to execute arbitrary code under Solaris OS. This vulnerability was publicly announced in the CERT Advisory CA-2002-11. All Cisco products and applications that are installed on Solaris OS are considered vulnerable to the underlying operating system vulnerability, unless the workaround was applied. This vulnerability is described in
CWE: CWE-119, CWE-119
GHSA
GHSA-j247-m687-9hwv: The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2
ghsa_unreviewed·2022-04-29
CVE-2003-1063 [HIGH] GHSA-j247-m687-9hwv: The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-56300-1http://www.ciac.org/ciac/bulletins/n-134.shtmlhttp://www.securityfocus.com/bid/8461https://exchange.xforce.ibmcloud.com/vulnerabilities/12942http://sunsolve.sun.com/search/document.do?assetkey=1-26-56300-1http://www.ciac.org/ciac/bulletins/n-134.shtmlhttp://www.securityfocus.com/bid/8461https://exchange.xforce.ibmcloud.com/vulnerabilities/12942
2003-08-20
Published