7.2
CVSSv2

CVE-1999-0689

Published: 13/09/1999 Updated: 30/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cde cde 2.120

cde cde 2.0

cde cde 2.1

cde cde 1.1

cde cde 1.2

cde cde 1.0.1

cde cde 1.0.2

sun solaris 7.0

sun sunos -

sun sunos 5.7

sun solaris 2.5

sun solaris 2.6

sun sunos 5.5

sun sunos 5.5.1

sun solaris 2.5.1

Exploits

#!/bin/sh # source: wwwsecurityfocuscom/bid/636/info # # This explanation is quoted from the initial post on this problem by Job De Hass This message is available in its entirety in the 'Credit' section of this vulnerability entry # # The CDE subprocess daemon /usr/dt/bin/dtspcd contains an insufficient check on client credentials The C ...