CVE-2008-0730

Solaris 10 - Unprotected User Data Exposure via Weak Permissions in Language Input Methods

Title source: llm
STIX 2.1

Description

The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0452
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28931
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27770
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-201315-1

Scores

EPSS 0.0008
EPSS Percentile 24.1%

Details

CWE
CWE-264
Status published
Products (1)
sun/solaris 10 (6 CPE variants)
Published Feb 12, 2008
Tracked Since Feb 18, 2026