Executive Summary

Summary
Title Sun Alert 270969 A Security Weakness in Solaris Trusted Extensions May Facilitate Privilege Escalation
Informations
Name SUN-270969 First vendor Publication 2009-10-26
Vendor Sun Last vendor Modification 2009-10-26
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10, OpenSolaris

A security weakness in Solaris Trusted Extensions Policy configuration
may allow a remote unprivileged user who has authorized or unauthorized
access to the X server, to leverage an additional vulnerability which could
lead to arbitrary code execution as a local privileged or unprivileged user.

State: Resolved
First released: 26-Oct-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_270969_a_security

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:6480
 
Oval ID: oval:org.mitre.oval:def:6480
Title: A Security Weakness in Solaris Trusted Extensions May Facilitate Privilege Escalation
Description: Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.
Family: unix Class: vulnerability
Reference(s): CVE-2009-3839
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 179
Os 2

Open Source Vulnerability Database (OSVDB)

Id Description
59354 Solaris Trusted Extensions Policy Unspecified Remote Bypass

Information Assurance Vulnerability Management (IAVM)

Date Description
2009-11-05 IAVM : 2009-A-0113 - Sun Solaris Remote Privilege Escalation Vulnerability
Severity : Category I - VMSKEY : V0021928

Nessus® Vulnerability Scanner

Date Description
2009-10-19 Name : The remote host is missing Sun Security Patch number 126363-10
File : solaris10_126363.nasl - Type : ACT_GATHER_INFO