Multiple Vendor Unix Domain Socket...

- AV AC AU C I A
发布: 1997-06-19
修订: 2025-04-13

Solaris 2.6 and many other unices/clones have a serious problem with their unix domain socket implementation that has it's origins in old BSD code. Any unix socket created by any application is set mode 4777. In Solaris versions 2.5 and earlier, the permissions were ignored completely. The applications are vulnerable to being connected to and written to by anyone. This could lead to a whole number of application-specific security compromises.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息