Back to search
CVE-2010-1183
Published: Mar 29, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20100324 Symlink attack with Solaris Update manager and Sun Patch Cluster
mailing-list
x_refsource_BUGTRAQ
38928
vdb-entry
x_refsource_BID
solaris-update-manager-multiple-symlink(57149)
vdb-entry
x_refsource_XF
20100324 Symlink attack with Solaris Update manager
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now