CVE-2006-4439: Low severity Sun Solaris vulnerability
pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4439?
CVE-2006-4439 is considered a moderate severity vulnerability due to the potential for local users to modify arbitrary files.
How do I fix CVE-2006-4439?
To fix CVE-2006-4439, ensure that the pkgadd utility is updated to a version released after August 25, 2006, where insecure permissions are addressed.
Who is affected by CVE-2006-4439?
CVE-2006-4439 affects local users on systems running Sun Solaris 10 prior to the specified version.
What are the potential consequences of CVE-2006-4439?
The consequences of CVE-2006-4439 include unauthorized modifications to files and directories by local users, potentially leading to system compromise.
Is CVE-2006-4439 a remote or local vulnerability?
CVE-2006-4439 is a local vulnerability, as it requires access to the system by an authenticated local user.