Executive Summary

Title Sun Alert 265908 A Security Vulnerability in the ZFS Filesystem May Allow An Unprivileged User to Take Ownership of Files Belonging to Another User
Name SUN-265908 First vendor Publication 2009-10-14
Vendor Sun Last vendor Modification 2009-12-04
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 4.4 Attack Range Local
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


Product: Solaris 10, OpenSolaris

A security vulnerability in the ZFS file system in OpenSolaris and Solaris 10 systems with patches 137137-09 (SPARC) or 137138-09 (x86) installed may allow a local unprivileged user with the 'file_chown_self' privilege to take ownership of files belonging to another user.

State: Resolved
First released: 14-Oct-2009

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_265908_a_security

CPE : Common Platform Enumeration

Os 36
Os 3

Open Source Vulnerability Database (OSVDB)

Id Description
59049 ZFS Filesystem on Solaris file_chown_self Privilege Local Restriction Bypass

Nessus® Vulnerability Scanner

Date Description
2009-10-15 Name : The remote host is missing Sun Security Patch number 141444-09
File : solaris10_141444.nasl - Type : ACT_GATHER_INFO
2009-10-15 Name : The remote host is missing Sun Security Patch number 141445-09
File : solaris10_x86_141445.nasl - Type : ACT_GATHER_INFO