CVE
- Id
- 1393
- CVE No.
- CVE-1999-1413
- Status
- Candidate
- Description
- Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
- Phase
- Proposed (20010912)
- Votes
- MODIFY(2) Dik, Frech | NOOP(2) Cole, Foat
- Comments
- Frech> XF:solaris-coredump-symlink(7196) | Dik> sun bug: 1208241 | | Also applies to set-uid executables that have made real | and effective uid identical