CVE-2003-1071

rpc.walld - Solaris 2.6-9 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1071. PoCs published by Brant Roman.

AI-analyzed exploit summary This exploit leverages a vulnerability in the Solaris 'wall' client where closing stderr allows spoofing the 'From' field in broadcast messages. It writes a crafted message to a temporary file and uses 'wall' to send it, appearing as if it originated from a specified user@host.

Description

rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Brant Roman · clocalsolaris
https://www.exploit-db.com/exploits/22120

This exploit leverages a vulnerability in the Solaris 'wall' client where closing stderr allows spoofing the 'From' field in broadcast messages. It writes a crafted message to a temporary file and uses 'wall' to send it, appearing as if it originated from a specified user@host.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Solaris wall client (versions affected by CVE-2003-1071)
No auth needed
Prerequisites: Access to a Solaris system with the vulnerable 'wall' client · Ability to execute arbitrary commands on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11608
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/305105
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6509
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1006682
Exploit, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/944241
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7825/
Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1005882

Scores

EPSS 0.0107
EPSS Percentile 60.6%

Details

Status published
Products (9)
sun/solaris 2.5.1
sun/solaris 2.6
sun/solaris 7.0
sun/solaris 8.0
sun/solaris 9.0
sun/sunos
sun/sunos 5.5.1
sun/sunos 5.7
sun/sunos 5.8
Published Jan 03, 2003
Tracked Since Feb 18, 2026