PT-2011-2747 · Sun · Sunos+1
Kingcope
·
Published
2011-02-07
·
Updated
2017-08-17
·
CVE-2011-0902
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SunScreen Firewall version on SunOS 5.9
Description
The issue concerns untrusted search path vulnerabilities in the Java Service of SunScreen Firewall on SunOS 5.9, allowing local users to execute arbitrary code. This can be achieved by modifying the
PATH or LD LIBRARY PATH environment variables.Recommendations
For SunScreen Firewall on SunOS 5.9, consider restricting access to the Java Service to minimize the risk of exploitation. As a temporary workaround, avoid using modified
PATH or LD LIBRARY PATH environment variables until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sunos
Sunscreen Firewall