PT-2007-3936 · Sun · Sun Solaris 10+1
Publicado
2007-05-11
·
Atualizado
2017-10-11
·
CVE-2007-2617
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Solaris 10
Description
The issue concerns the srsexec component in Sun Remote Services (SRS) Net Connect Software Proxy Core package, which fails to enforce file permissions when opening files. This allows local users to read the first line of arbitrary files by utilizing the -d and -v options.
Recommendations
For Sun Solaris 10, consider restricting access to the srsexec component until a fix is available, and avoid using the -d and -v options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sun Remote Services (Srs) Net Connect Software Proxy Core
Sun Solaris 10