CVE-2006-4439 Information

Description

pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a ?\ (question mark) in the mode field which allows local users to modify arbitrary files or directories a different vulnerability than CVE-2002-1871.

Reference

http://secunia.com/advisories/21633 http://secunia.com/advisories/22992 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102513-1 http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm http://www.osvdb.org/28203 http://www.securityfocus.com/bid/19730 http://www.vupen.com/english/advisories/2006/3397 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A2010

Share on: