pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a ? (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Solaris | Sun | 2.6 (including) | 2.6 (including) |
| Sunos | Sun | 5.5.1 (including) | 5.5.1 (including) |
| Sunos | Sun | 5.7 (including) | 5.7 (including) |
| Sunos | Sun | 5.8 (including) | 5.8 (including) |