CVE-2004-0481Solaris vulnerability

3 documents3 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 83.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateApr 29

Description

The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDsun/solaris8.0, 9.0+1
NVDsun/sunos5.8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-55w2-52pp-35qg: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary fil2022-04-29
CVEList
CVE-2004-0481: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary fil2005-02-24
CVE-2004-0481 — SUN Solaris vulnerability | cvebase