PT-2007-3936 · Sun · Sun Solaris 10+1

Published

2007-05-11

·

Updated

2017-10-11

·

CVE-2007-2617

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Solaris 10
Description The issue concerns the srsexec component in Sun Remote Services (SRS) Net Connect Software Proxy Core package, which fails to enforce file permissions when opening files. This allows local users to read the first line of arbitrary files by utilizing the -d and -v options.
Recommendations For Sun Solaris 10, consider restricting access to the srsexec component until a fix is available, and avoid using the -d and -v options to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2617

Affected Products

Sun Remote Services (Srs) Net Connect Software Proxy Core
Sun Solaris 10