The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Software | From | Fixed in |
---|---|---|
cde / cde | 1.0.1 | 1.0.1.x |
cde / cde | 1.0.2 | 1.0.2.x |
cde / cde | 1.1 | 1.1.x |
cde / cde | 2.1 | 2.1.x |
cde / cde | 1.2 | 1.2.x |
cde / cde | 2.120 | 2.120.x |
cde / cde | 2.0 | 2.0.x |
sun / solaris | 2.5.1 | 2.5.1.x |
sun / solaris | 2.5 | 2.5.x |
sun / sunos | 5.7 | 5.7.x |
sun / sunos | 5.5 | 5.5.x |
sun / solaris | 7.0 | 7.0.x |
sun / sunos | 5.5.1 | 5.5.1.x |
sun / solaris | 2.6 | 2.6.x |