Vulnerabilities > CVE-1999-0689

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
cde
sun
exploit available

Summary

The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.

Exploit-Db

descriptionCommon Desktop Environment 2.1 20,Solaris 7.0 dtspcd Vulnerability. CVE-1999-0689 . Local exploits for multiple platform
idEDB-ID:19498
last seen2016-02-02
modified1999-09-13
published1999-09-13
reporterJob de Haas of ITSX
sourcehttps://www.exploit-db.com/download/19498/
titleCommon Desktop Environment <= 2.1 20,Solaris <= 7.0 dtspcd Vulnerability

Oval

accepted2005-03-09T07:56:00.000-04:00
classvulnerability
contributors
nameBrian Soby
organizationThe MITRE Corporation
descriptionThe CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
familyunix
idoval:org.mitre.oval:def:1880
statusaccepted
submitted2005-02-01T12:00:00.000-04:00
titleCDE dtspcd Daemon Symlink Vulnerability
version35