First published: Tue Dec 31 2002(Updated: )
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Solaris PC NetLink | =1.1 | |
Sun Solaris PC NetLink | =1.2 | |
Sun Solaris PC NetLink | =1.0 | |
Sun Solaris PC NetLink | >=1.0<=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2323 is rated as a medium severity vulnerability due to improper access control allowing potential bypass by attackers.
To fix CVE-2002-2323, ensure that the access control lists for files and directories are correctly set after restoring from backups.
CVE-2002-2323 affects users of Sun PC NetLink versions 1.0 through 1.2.
Yes, CVE-2002-2323 can be exploited by both local and remote attackers due to improper ACL settings.
The potential impacts of CVE-2002-2323 include unauthorized access to files and directories that should be restricted.