Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Jun 16, 2026
CVE-2002-1871
CVE-2002-1871
Description
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Affected products
5cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:*
- (no CPE)range: 2.5.1 through 8
cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*
- cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:*
- cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- sunsolve.sun.com/search/document.donvdPatchVendor Advisory
- www.iss.net/security_center/static/9544.phpnvdPatch
- www.securityfocus.com/bid/5208nvdPatch
News mentions
0No linked articles in our index yet.