Executive Summary

Summary
Title Sun Alert 267488 Security Vulnerabilities in Solaris Trusted Extensions Common Desktop Environment (CDE) may allow Privilege Escalation or Mandatory Access Control (MAC) Policy Violation
Informations
Name SUN-267488 First vendor Publication 2009-09-23
Vendor Sun Last vendor Modification 2009-09-23
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 6.9 Attack Range Local
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10 Operating System

Security Vulnerabilities in Solaris Trusted Extensions Common Desktop Environment (CDE)
may allow an unprivileged local user to easily execute arbitrary commands with root privileges
or to bypass Mandatory Access Control (MAC) policy.


State: Resolved
First released: 23-Sep-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_267488_security_vulnerabilities

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2

OpenVAS Exploits

Date Description
2009-10-13 Name : Solaris Update for CDE 1.6 139620-01
File : nvt/gb_solaris_139620_01.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
58319 Solaris Trusted Extensions Common Desktop Environment (CDE) Unspecified Local...

Information Assurance Vulnerability Management (IAVM)

Date Description
2009-10-01 IAVM : 2009-A-0085 - Multiple Vulnerabilities in Solaris Trusted Extensions Common Desktop Environ...
Severity : Category I - VMSKEY : V0021628

Nessus® Vulnerability Scanner

Date Description
2009-09-23 Name : The remote host is missing Sun Security Patch number 126365-16
File : solaris10_126365.nasl - Type : ACT_GATHER_INFO
2009-09-23 Name : The remote host is missing Sun Security Patch number 139620-01
File : solaris10_139620.nasl - Type : ACT_GATHER_INFO
2009-09-23 Name : The remote host is missing Sun Security Patch number 126366-16
File : solaris10_x86_126366.nasl - Type : ACT_GATHER_INFO
2009-09-23 Name : The remote host is missing Sun Security Patch number 139621-01
File : solaris10_x86_139621.nasl - Type : ACT_GATHER_INFO