HIGH
The U.S
Published Dec 4, 2009
9.3
HIGHCVSS 2.0
EPSS 1.69%
Description
The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.
Affected products
No data.
AND
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://securitytracker.com/id?1023265 vdb-entryx_refsource_SECTRACK
- http://www.kb.cert.org/vuls/id/433821 third-party-advisoryx_refsource_CERT-VN
- http://www.securityfocus.com/archive/1/508188/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/37200 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4181 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://securitytracker.com/id?1023265 | vdb-entryx_refsource_SECTRACK | |
| http://www.kb.cert.org/vuls/id/433821 | third-party-advisoryx_refsource_CERT-VN | |
| http://www.securityfocus.com/archive/1/508188/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/37200 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4181 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 4, 2009
Updated Aug 7, 2024
Reserved Dec 4, 2009
Link CVE-2009-4211
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data