First published: Mon Mar 29 2010(Updated: )
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris and Zettabyte File System (ZFS) | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1183 is considered a high-severity vulnerability due to its potential for local privilege escalation.
To mitigate CVE-2010-1183, ensure that updates are applied to Oracle Solaris that address this vulnerability.
CVE-2010-1183 affects local users of Oracle Solaris who can exploit the symlink vulnerability.
CVE-2010-1183 is associated with a symlink attack that allows data to be appended to arbitrary files.
CVE-2010-1183 was disclosed in 2010 as part of security vulnerabilities in Oracle Solaris.