Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2003-1575


VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.


Published

2010-01-28T20:30:00.823

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application symantec vxfs 3.3.3 Yes
Operating System sun solaris 2.5.1 No
Operating System sun solaris 2.6 No
Operating System sun solaris 7.0 No
Operating System sun solaris 8.0 No
Application symantec vxfs 3.4 Yes
Application symantec vxfs 3.5 Yes
Operating System sun solaris 7.0 No
Operating System sun solaris 8.0 No
Operating System sun solaris 9.0 No

References