VYPR
Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Jun 16, 2026

CVE-2002-1871

CVE-2002-1871

Description

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.

Affected products

5
  • cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:*
    • (no CPE)range: 2.5.1 through 8
  • cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*
    • cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:*
    • cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.