CVE-2004-0481: Low severity sunos vulnerability
Published Feb 23, 2005
·Updated
The logging feature in kcmsconfigure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCSClogFile file.
Affected Software
4 affected components
Sun SunOS=5.8
Sun Solaris=9.0
Sun Solaris=9.0
Sun Solaris=8.0
Remediation
Event History
Feb 23, 2005
CVE Published
05:00 AM
Feb 24, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0481?
CVE-2004-0481 is classified as a medium severity vulnerability due to its potential for local exploitation.
2
How do I fix CVE-2004-0481?
To fix CVE-2004-0481, ensure that proper permissions are set on the KCS_ClogFile to prevent symlink attacks.
3
Who is affected by CVE-2004-0481?
CVE-2004-0481 affects local users on Solaris 8 and 9 systems.
4
What type of attack does CVE-2004-0481 involve?
CVE-2004-0481 involves a symlink attack that allows local users to corrupt arbitrary files.
5
What software versions are affected by CVE-2004-0481?
CVE-2004-0481 affects KCMS package versions on Solaris 8 and 9 operating systems.