CVE-2003-1073: Race Condition
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1073?
CVE-2003-1073 is classified as a moderate severity vulnerability due to its impact on local user file deletion.
How does CVE-2003-1073 work?
CVE-2003-1073 exploits a race condition in the at command allowing users to delete arbitrary files through modified job names.
Who is affected by CVE-2003-1073?
CVE-2003-1073 affects local users on Solaris versions 2.6 through 9, inclusive.
How can I protect my system from CVE-2003-1073?
To protect against CVE-2003-1073, avoid using the at command with untrusted input and restrict local user permissions.
Is there a patch available for CVE-2003-1073?
While specific patches may vary, users should consult their Solaris documentation for recommended updates to mitigate CVE-2003-1073.