vendor:
Sun Connection Update Manager for Solaris
by:
Larry W. Cashdollar
7.5
CVSS
HIGH
Insecure Temporary File Creation
377
CWE
Product Name: Sun Connection Update Manager for Solaris
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Insecure Temporary File Creation in Sun Connection Update Manager for Solaris
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application. Successfully mounting a symlink attack may allow the attacker to overwrite or corrupt sensitive files, which may result in a denial-of-service or privilege escalation. Other attacks may also be possible.
Mitigation:
Unknown