Executive Summary

Summary
Title Sun Alert 231803 Security Vulnerability in the Solaris 10 DTrace Dynamic Tracing Framework May Allow Unauthorized Kernel Level Tracing
Informations
Name SUN-231803 First vendor Publication 2008-04-28
Vendor Sun Last vendor Modification 2008-04-28
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:N/A:N)
Cvss Base Score 4.7 Attack Range Local
Cvss Impact Score 6.9 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10 Operating System

A security vulnerability in the Solaris 10 DTrace (see dtrace(1M)) dynamic tracing framework may allow a local user or a non-global zone which has been granted either the PRIV_DTRACE_USER or the PRIV_DTRACE_PROC privilege (see privileges(5)) to be able to perform some kernel-level tracing.?? Such users may then be able to access sensitive information.

State: Resolved
First released: 28-Apr-2008

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_231803_security_vulnerability

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-200 Information Exposure

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:5451
 
Oval ID: oval:org.mitre.oval:def:5451
Title: Security Vulnerability in the Solaris 10 DTrace Dynamic Tracing Framework May Allow Unauthorized Kernel Level Tracing
Description: Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.
Family: unix Class: vulnerability
Reference(s): CVE-2008-0938
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2

Open Source Vulnerability Database (OSVDB)

Id Description
42021 Solaris 10 DTrace Dynamic Tracing Framework Kernel Tracing Information Disclo...

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2013-02-06 19:08:12
  • Multiple Updates