First published: Tue Aug 29 2006(Updated: )
pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4439 is considered a moderate severity vulnerability due to the potential for local users to modify arbitrary files.
To fix CVE-2006-4439, ensure that the pkgadd utility is updated to a version released after August 25, 2006, where insecure permissions are addressed.
CVE-2006-4439 affects local users on systems running Sun Solaris 10 prior to the specified version.
The consequences of CVE-2006-4439 include unauthorized modifications to files and directories by local users, potentially leading to system compromise.
CVE-2006-4439 is a local vulnerability, as it requires access to the system by an authenticated local user.