LOW · 2.6

CVE-2007-0895

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm ...

Vulnerability Description

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

CVSS Score

2.6

LOW

AV:L/AC:H/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SunSolaris9.0
SunSunos5.8

References

FAQ

What is CVE-2007-0895?

CVE-2007-0895 is a vulnerability with a CVSS score of 2.6 (LOW). Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm ...

How severe is CVE-2007-0895?

CVE-2007-0895 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0895?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris, Sun Sunos.