Vulnerability Details CVE-2002-1871
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.5%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2002-1871
-
cpe:2.3:o:sun:solaris:2.6
-
cpe:2.3:o:sun:sunos:5.5.1
-
-