Vulnerabilities > CVE-1999-1413 - Unspecified vulnerability in SUN Solaris and Sunos

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
sun
exploit available

Summary

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

Vulnerable Configurations

Part Description Count
OS
Sun
2

Exploit-Db

descriptionSolaris 7.0 Coredump Vulnerbility. CVE-1999-1413 . Remote exploit for solaris platform
idEDB-ID:19236
last seen2016-02-02
modified1996-08-03
published1996-08-03
reporterJungseok Roh
sourcehttps://www.exploit-db.com/download/19236/
titleSolaris <= 7.0 Coredump Vulnerbility