CVE Vulnerabilities

CVE-2002-1871

Published: Dec 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a ? (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.

Affected Software

NameVendorStart VersionEnd Version
SolarisSun2.6 (including)2.6 (including)
SunosSun5.5.1 (including)5.5.1 (including)
SunosSun5.7 (including)5.7 (including)
SunosSun5.8 (including)5.8 (including)

References