PT-2009-3464 · Sun · Sun Solaris+1

Published

2009-03-11

·

Updated

2017-08-17

·

CVE-2009-0872

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Solaris versions 10 OpenSolaris versions prior to snv 111
Description The issue concerns the NFS server's improper implementation of the AUTH NONE security mode when combined with other security modes. This allows remote attackers to bypass access restrictions, enabling them to read or modify files. An example of this vulnerability is when AUTH NONE is used in combination with AUTH SYS.
Recommendations For Sun Solaris 10, consider restricting access to the NFS server until a proper fix is applied. For OpenSolaris versions prior to snv 111, update to a version after snv 111 to resolve the issue. As a temporary workaround, consider disabling the use of the AUTH NONE security mode in combination with other modes until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0872

Affected Products

Opensolaris
Sun Solaris