4.6
CVSSv2

CVE-1999-1413

Published: 03/08/1996 Updated: 30/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunos 5.4

sun solaris 2.4

Exploits

source: wwwsecurityfocuscom/bid/296/info There is a vulnerability in the way Solaris 24 pre Jumbo Kernel Patch -35 (for SPARC) dumps core files Under normal operation the operating system writes out a core image of a process when it is terminated due to the receipt of some signals The core image is called core and is written in the pro ...