7.2
CVSSv2

CVE-1999-0410

Published: 05/03/1999 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunos -

Exploits

/* source: wwwsecurityfocuscom/bid/293/info A buffer overrun condition was discovered in Solaris 26 X_86 in /usr/bin/cancel This buffer overflow is apparently present in the SPARC version as well although it is thought to be unexploitable Previous versions of Solaris did not ship with /usr/bin/cancel as SUID root, so while the buffer o ...