CVE-2004-0481 — Solaris vulnerability
3 documents3 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 83.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateApr 29
Description
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
CVSS vector
AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-55w2-52pp-35qg: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary fil↗2022-04-29
CVEList▶
CVE-2004-0481: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary fil↗2005-02-24