PT-2008-6751 · Sun · Sun Solaris+1

Publicado

2008-12-22

·

Atualizado

2009-01-06

·

CVE-2008-5699

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 10 and OpenSolaris snv 50 through snv 104
Description The issue is related to the name service cache daemon (nscd) not properly checking permissions. This allows local users to gain privileges and obtain sensitive information.
Recommendations For Sun Solaris 10 and OpenSolaris snv 50 through snv 104, consider restricting access to the nscd daemon until a proper fix is available. As a temporary workaround, review and tighten permissions on sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5699

Produtos afetados

Opensolaris
Sun Solaris