PT-2009-3464 · Sun · Sun Solaris+1
Publicado
2009-03-11
·
Atualizado
2017-08-17
·
CVE-2009-0872
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 10
OpenSolaris versions prior to snv 111
Description
The issue concerns the NFS server's improper implementation of the AUTH NONE security mode when combined with other security modes. This allows remote attackers to bypass access restrictions, enabling them to read or modify files. An example of this vulnerability is when AUTH NONE is used in combination with AUTH SYS.
Recommendations
For Sun Solaris 10, consider restricting access to the NFS server until a proper fix is applied.
For OpenSolaris versions prior to snv 111, update to a version after snv 111 to resolve the issue.
As a temporary workaround, consider disabling the use of the AUTH NONE security mode in combination with other modes until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opensolaris
Sun Solaris