Vulnerability Note VU#281356

Sun Solaris tcsh(1) contains vulnerability in the built-in ls-F command

Original Release date: 15 Jan 2004 | Last revised: 16 Jan 2004

Overview

Sun Solaris tcsh(1) contains a vulnerability in the built-in ls-F command that could allow an unprivileged user to create or remove files or gain privileges of another user.

Description

A vulnerability in the built-in ls-F command of the Sun Solaris tcsh(1) may allow an intruder to create or remove files or gain privileges of another user. Note that only Solaris 8 is affected by this issue. Solaris 7 and 9 are not affected.

Impact

A local user could create or remove files or gain privileges of another user, possibly root.

Solution

Apply Patch

Apply a patch. For information about the patches, please see Sun Alert ID: 57455.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Sun Microsystems Inc.Affected-16 Jan 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

Thanks to Sun Microsystems for the information contained in their security advisory.

This document was written by Damon Morda.

Other Information

  • CVE IDs: CAN-2003-1024
  • Date Public: 22 Dec 2003
  • Date First Published: 15 Jan 2004
  • Date Last Updated: 16 Jan 2004
  • Severity Metric: 3.07
  • Document Revision: 15

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.