Vulnerabilities > CVE-2003-1073 - Unspecified vulnerability in SUN Solaris and Sunos

047910
CVSS 1.2 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
high complexity
sun
exploit available

Summary

A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.

Exploit-Db

descriptionSun Solaris 2.5/2.6/7.0/8/9 AT Command Arbitrary File Deletion Vulnerability. CVE-2003-1073. Local exploit for solaris platform
idEDB-ID:22203
last seen2016-02-02
modified2003-01-27
published2003-01-27
reporterWojciech Purczynski
sourcehttps://www.exploit-db.com/download/22203/
titleSun Solaris 2.5/2.6/7.0/8/9 AT Command Arbitrary File Deletion Vulnerability