CVE Vulnerabilities

CVE-2002-1296

Published: Dec 23, 2002 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via .. sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

Affected Software

Name Vendor Start Version End Version
Solaris Sun 2.6 (including) 2.6 (including)
Solaris Sun 7.0 (including) 7.0 (including)
Solaris Sun 8.0 (including) 8.0 (including)
Solaris Sun 9.0 (including) 9.0 (including)
Sunos Sun 5.5.1 (including) 5.5.1 (including)
Sunos Sun 5.7 (including) 5.7 (including)
Sunos Sun 5.8 (including) 5.8 (including)

References