Executive Summary

Summary
Title Sun Alert 103029 Two Security Vulnerabilities in Solaris 8 Role Based Access Control (rbac(5)) may Allow Unauthorized Remote Access
Informations
Name SUN-103029 First vendor Publication 2007-08-16
Vendor Sun Last vendor Modification 2007-08-17
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.6 Attack Range Network
Cvss Impact Score 10 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 8 Operating System

Two security vulnerabilities in the Solaris 8 Role Based Access Control (RBAC) mechanism on hosts on which RBAC roles (see rbac(5)) have been created may allow a remote user who knows the passwords for certain roles to gain unauthorized access to the system via the role accounts. If the root user has been assigned a role, a remote user who knows the password for that role may gain unauthorized root privileges on the system.

Avoidance: Patch, Workaround
State: Resolved
First released: 16-Aug-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_103029_two_security

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:1941
 
Oval ID: oval:org.mitre.oval:def:1941
Title: Two Security Vulnerabilities in Solaris 8 Role Based Access Control (rbac(5)) may Allow Unauthorized Remote Access
Description: Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun Solaris 8 allow remote attackers who know the password for a role to gain privileges via that role.
Family: unix Class: vulnerability
Reference(s): CVE-2007-4395
Version: 1
Platform(s): Sun Solaris 8
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1

OpenVAS Exploits

Date Description
2009-06-03 Name : Solaris Update for pam_roles.so 127033-01
File : nvt/gb_solaris_127033_01.nasl
2009-06-03 Name : Solaris Update for pam_roles.so 127034-01
File : nvt/gb_solaris_127034_01.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
36614 Solaris Role Based Access Control (RBAC) Unspecified Remote Role Privilege Es...

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2016-04-26 18:14:41
  • Multiple Updates