PT-2007-3936 · Sun · Sun Solaris 10+1
Published
2007-05-11
·
Updated
2017-10-11
·
CVE-2007-2617
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Solaris 10
Description
The issue concerns the srsexec component in Sun Remote Services (SRS) Net Connect Software Proxy Core package, which fails to enforce file permissions when opening files. This allows local users to read the first line of arbitrary files by utilizing the -d and -v options.
Recommendations
For Sun Solaris 10, consider restricting access to the srsexec component until a fix is available, and avoid using the -d and -v options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Remote Services (Srs) Net Connect Software Proxy Core
Sun Solaris 10