
Find real vulnerabilities before they ship
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
| Base Score | 4.6 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |