CVE-2001-0059 describes a symlink attack vulnerability in the patchadd utility within Solaris operating systems (versions 2.5.1, 2.6, 7.0, and 8). This flaw allows local users to overwrite arbitrary files, posing a significant risk to system integrity. Rated with a CVSS score of 6.2 (Medium), it requires high attack complexity but grants complete confidentiality, integrity, and availability impact. While not actively exploited in the wild or listed in CISA KEV, an exploit demonstrating a race condition is available on ExploitDB, and it has garnered notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.