pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-967-1 New elog packages fix arbitrary code execution
EUVD EUVD EUVD-2006-4427 pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T19:06:07.668Z

Reserved: 2006-08-29T00:00:00

Link: CVE-2006-4439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-08-29T23:04:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-4439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.