CVE-2009-4211
Published Dec 4, 2009
Last updated 6 years ago
Overview
- Description
- The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:sun:solaris:*:*:x86:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FEEC0C5A-4A6E-403C-B929-D1EC8B0FE2A8" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:disa:srr_for_solaris:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2B2F07A-2013-43C0-B408-72AE19B2E358" } ], "operator": "OR" } ], "operator": "AND" } ]