4.6
CVSSv2

CVE-1999-0786

Published: 22/09/1999 Updated: 30/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sun solaris 2.4

sun solaris 2.5.1

sun solaris 2.5

sun sunos 5.5

sun sunos 5.4

sun sunos 5.5.1

sun solaris 2.6

sun sunos -

Exploits

source: wwwsecurityfocuscom/bid/659/info A vulnerability in the dynamic linkers while profiling a shared object allows local users to create arbitrary files in the system It canno't be used to overwrite existing files If the LD_PROFILE environment variable is defined it instructs the dynamic linker to profile the shared object defined ...