PT-2007-3936 · Sun · Sun Solaris 10+1

Publicado

2007-05-11

·

Atualizado

2017-10-11

·

CVE-2007-2617

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Solaris 10
Description The issue concerns the srsexec component in Sun Remote Services (SRS) Net Connect Software Proxy Core package, which fails to enforce file permissions when opening files. This allows local users to read the first line of arbitrary files by utilizing the -d and -v options.
Recommendations For Sun Solaris 10, consider restricting access to the srsexec component until a fix is available, and avoid using the -d and -v options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2617

Produtos afetados

Sun Remote Services (Srs) Net Connect Software Proxy Core
Sun Solaris 10