CVE-2003-1073: Race Condition

Published Dec 31, 2003
·
Updated

A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.

Affected Software

10 affected components
Sun SunOS=5.7
Sun SunOS=5.5
Sun SunOS=5.8
Sun Solaris=9.0
Sun Solaris=7.0
Sun Solaris=9.0
Sun SunOS=5.5.1
Sun Solaris=2.6
Sun Solaris=8.0
Sun SunOS

Remediation

Event History

Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Feb 8, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2003-1073?

CVE-2003-1073 is classified as a moderate severity vulnerability due to its impact on local user file deletion.

2

How does CVE-2003-1073 work?

CVE-2003-1073 exploits a race condition in the at command allowing users to delete arbitrary files through modified job names.

3

Who is affected by CVE-2003-1073?

CVE-2003-1073 affects local users on Solaris versions 2.6 through 9, inclusive.

4

How can I protect my system from CVE-2003-1073?

To protect against CVE-2003-1073, avoid using the at command with untrusted input and restrict local user permissions.

5

Is there a patch available for CVE-2003-1073?

While specific patches may vary, users should consult their Solaris documentation for recommended updates to mitigate CVE-2003-1073.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203