← Back

CVE-2007-0895

nvd nist
Published: Feb 13, 2007Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:L/AC:H/Au:N/C:N/I:P/A:P
Exploitability: 1.9 / Impact: 4.9
Source: NVD

Description

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

Affected (3)

Products: Sun: Solaris, Sunos
2 products
Solaris
Sunos
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 10.0
Version 9.0
Version 5.8

References (16)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.