7.2
CVSSv2

CVE-1999-1433

Published: 15/07/1998 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.

Vulnerable Product Search on Vulmon Subscribe to Product

hp jetadmin rev._d.01.09

Exploits

source: wwwsecurityfocuscom/bid/157/info A vulnerability exists in HP's JetAdmin Rev D0109 software Due to its failure to check if it is following a symbolic link, it is possible for an attacker to create a link from /tmp/jetadminlog to anywhere on the filesystem, with permissions for reading and writing by everyone on the system Th ...