CVE-2010-1183

Oracle Solaris - Info Disclosure

Title source: llm

Description

Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Larry W. Cashdollar · bashlocalsolaris
https://www.exploit-db.com/exploits/33799
exploitdb WORKING POC
by Larry W. Cashdollar · textlocallinux_x86
https://www.exploit-db.com/exploits/26709
exploitdb WORKING POC
by Larry Cashdollar · textlocalsolaris
https://www.exploit-db.com/exploits/20418

Scores

EPSS 0.0016
EPSS Percentile 37.1%

Details

CWE
CWE-59
Status published
Products (1)
sun/solaris
Published Mar 29, 2010
Tracked Since Feb 18, 2026