PT-2009-3464 · Sun · Sun Solaris+1
Published
2009-03-11
·
Updated
2017-08-17
·
CVE-2009-0872
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 10
OpenSolaris versions prior to snv 111
Description
The issue concerns the NFS server's improper implementation of the AUTH NONE security mode when combined with other security modes. This allows remote attackers to bypass access restrictions, enabling them to read or modify files. An example of this vulnerability is when AUTH NONE is used in combination with AUTH SYS.
Recommendations
For Sun Solaris 10, consider restricting access to the NFS server until a proper fix is applied.
For OpenSolaris versions prior to snv 111, update to a version after snv 111 to resolve the issue.
As a temporary workaround, consider disabling the use of the AUTH NONE security mode in combination with other modes until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensolaris
Sun Solaris