CVE
- Id
- 840
- CVE No.
- CVE-1999-0860
- Status
- Candidate
- Description
- Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
- Phase
- Proposed (19991208)
- Votes
- ACCEPT(2) Armstrong, Stracener | MODIFY(2) Dik, Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | REVIEWING(1) Prosser
- Comments
- Cole> This is the same as the pervious. | Frech> XF:sol-chkperm-vmsys | Dik> include reference to Sun bug 4296167 | Christey> Remove BID:837, which is for arp, not chkperm