CVE Vulnerabilities

CVE-2002-1296

Published: Dec 23, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via .. sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

Affected Software

NameVendorStart VersionEnd Version
SolarisSun2.6 (including)2.6 (including)
SolarisSun7.0 (including)7.0 (including)
SolarisSun8.0 (including)8.0 (including)
SolarisSun9.0 (including)9.0 (including)
SunosSun5.5.1 (including)5.5.1 (including)
SunosSun5.7 (including)5.7 (including)
SunosSun5.8 (including)5.8 (including)

References