CVE-2003-1073
Last modified
CVE-2003-1073 is a vulnerability of currently unknown severity. A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Solaris | 2.6 |
| Sun | Solaris | 7.0 |
| Sun | Solaris | 8.0 |
| Sun | Solaris | 9.0 |
| Sun | Sunos | All versions |
| Sun | Sunos | 5.5 |
| Sun | Sunos | 5.5.1 |
| Sun | Sunos | 5.7 |
| Sun | Sunos | 5.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1073?
How severe is CVE-2003-1073?
How do I fix CVE-2003-1073?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1067Multiple buffer overflows in the (1) dbm_open function, as u…
- CVE-2003-1068Buffer overflow in utmp_update for Solaris 2.6 through 9 all…
- CVE-2003-1069The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 all…
- CVE-2003-1070Unknown vulnerability in rpcbind for Solaris 2.6 through 9 a…
- CVE-2003-1071rpc.walld (wall daemon) for Solaris 2.6 through 9 allows loc…
- CVE-2003-1072Memory leak in lofiadm in Solaris 8 allows local users to ca…
- CVE-2003-1074Unknown vulnerability in newtask for Solaris 9 allows local …
- CVE-2003-1075Unknown vulnerability in the FTP server (in.ftpd) for Solari…
- CVE-2003-1076Unknown vulnerability in sendmail for Solaris 7, 8, and 9 al…
- CVE-2003-1077Unknown vulnerability in UFS for Solaris 9 for SPARC, with l…
- CVE-2003-1078The FTP client for Solaris 2.6, 7, and 8 with the debug (-d)…
- CVE-2003-1079Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9…
Are you affected by CVE-2003-1073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
