CVE-2003-1073
LOW 1.2EPSS 0.7%
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
- CVSS v2.0
- 1.2 LOW
AV:L/AC:H/Au:N/C:N/I:P/A:N - EPSS
- 0.69% chance of exploitation in the next 30 days, 50th percentile
- Published
- 2005-02-08
- Updated
- 2024-08-08