Overview
The Sun Management Center (SunMC) contains a vulnerability that could allow an attacker to create or overwrite any file on the system.
Description
| An unknown vulnerability exists in the Sun Management Center (SunMC), according to a Sun Alert Notification. According to that document, "unprivileged local users may be able to overwrite or create any file" if SunMC is installed setuid root. No other details are available. | 
Impact
| An attacker can create or overwrite any file on the system, which can be leveraged to gain root access. | 
Solution
| Apply a patch as described in the Sun Alert Notification. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to Sun Microsystems for reporting this vulnerability.
This document was written by Shawn V Hernan based on information provided by Sun Microsystems.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 12.02 | 
| Date Public: | 2003-06-16 | 
| Date First Published: | 2003-06-23 | 
| Date Last Updated: | 2003-06-23 18:56 UTC | 
| Document Revision: | 3 |