Executive Summary

Summary
Title Sun Alert 253588 Security Vulnerability in the Solaris NFS Server Security Modes (nfssec(5)) may Lead to Unauthorized Access to Shared Resources
Informations
Name SUN-253588 First vendor Publication 2009-03-09
Vendor Sun Last vendor Modification 2009-03-30
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in the Solaris NFS server may lead to unauthorized access to file systems shared via NFS if those resources are shared using a combination of "none" (AUTH_NONE) and "sys" (AUTH_SYS) (see nfssec(5)) security modes.
State: Resolved
First released: 09-Mar-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_253588_security_vulnerability

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 351
Os 1

OpenVAS Exploits

Date Description
2009-06-03 Name : Solaris Update for Obsoleted by 139462-02
File : nvt/gb_solaris_139462_02.nasl
2009-06-03 Name : Solaris Update for Obsoleted by 139463-02
File : nvt/gb_solaris_139463_02.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
52559 Solaris NFS Server Security Modes (nfssec(5)) Combined AUTH_NONE / AUTH_SYS A...