// For flags

CVE-2003-1575

 

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.

VERITAS File System (VxFS) v3.3.3, v3.4, y v3.5 anterior a MP1 Rolling Patch 02 para Sun Solaris v2.5.1 a la v9, no implementa adecuadamente la herencia de las ACLs por defecto en determinadas circunstancias relacionadas con las características de un directorio inode, lo que permite a usuarios locales evitar las restricciones de acceso a archivos establecidas accediendo a un archivo sobre un sistema de ficheros VxFS.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-01-28 CVE Reserved
  • 2010-01-28 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.3.3
Search vendor "Symantec" for product "Vxfs" and version "3.3.3"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
2.5.1
Search vendor "Sun" for product "Solaris" and version "2.5.1"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.3.3
Search vendor "Symantec" for product "Vxfs" and version "3.3.3"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
2.6
Search vendor "Sun" for product "Solaris" and version "2.6"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.3.3
Search vendor "Symantec" for product "Vxfs" and version "3.3.3"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
7.0
Search vendor "Sun" for product "Solaris" and version "7.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.3.3
Search vendor "Symantec" for product "Vxfs" and version "3.3.3"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
8.0
Search vendor "Sun" for product "Solaris" and version "8.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.4
Search vendor "Symantec" for product "Vxfs" and version "3.4"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
7.0
Search vendor "Sun" for product "Solaris" and version "7.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.4
Search vendor "Symantec" for product "Vxfs" and version "3.4"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
8.0
Search vendor "Sun" for product "Solaris" and version "8.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.4
Search vendor "Symantec" for product "Vxfs" and version "3.4"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
9.0
Search vendor "Sun" for product "Solaris" and version "9.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.5
Search vendor "Symantec" for product "Vxfs" and version "3.5"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
7.0
Search vendor "Sun" for product "Solaris" and version "7.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.5
Search vendor "Symantec" for product "Vxfs" and version "3.5"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
8.0
Search vendor "Sun" for product "Solaris" and version "8.0"
sparc
Safe
Symantec
Search vendor "Symantec"
Vxfs
Search vendor "Symantec" for product "Vxfs"
3.5
Search vendor "Symantec" for product "Vxfs" and version "3.5"
-
Affected
in Sun
Search vendor "Sun"
Solaris
Search vendor "Sun" for product "Solaris"
9.0
Search vendor "Sun" for product "Solaris" and version "9.0"
sparc
Safe