PT-2004-3200 · Sun · Sun Solaris
Published
2004-12-31
·
Updated
2018-10-30
·
CVE-2004-2306
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Sun Solaris versions 7 through 9
Description:
The issue occurs when the Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed due to security hardening. This configuration disables mail alerts from the audit warn script, potentially allowing attackers to evade detection.
Recommendations:
For Sun Solaris versions 7 through 9, consider re-enabling or reinstalling the SUNWscpu package to restore mail alerts from the audit warn script, or implement an alternative monitoring solution to detect potential security incidents.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris