PT-2009-4714 · Sun · Sun Solaris 10+1

Published

2009-07-01

·

Updated

2024-01-26

·

CVE-2009-2282

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Solaris 10 OpenSolaris versions snv 41 through snv 108
Description The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) on SPARC platforms does not check authorization for guest console access. This allows local control-domain users to gain guest-domain privileges via unknown vectors.
Recommendations For Sun Solaris 10, update the system to include the fix for the authorization issue in the Virtual Network Terminal Server daemon. For OpenSolaris versions snv 41 through snv 108, update the system to a version outside of this range to ensure the inclusion of the fix for the authorization issue in the Virtual Network Terminal Server daemon.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2009-2282

Affected Products

Opensolaris
Sun Solaris 10