PT-2009-4714 · Sun · Sun Solaris 10+1

CVE-2009-2282

·

Publicado

2009-07-01

·

Atualizado

2024-01-26

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Solaris 10 OpenSolaris versions snv 41 through snv 108
Description The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) on SPARC platforms does not check authorization for guest console access. This allows local control-domain users to gain guest-domain privileges via unknown vectors.
Recommendations For Sun Solaris 10, update the system to include the fix for the authorization issue in the Virtual Network Terminal Server daemon. For OpenSolaris versions snv 41 through snv 108, update the system to a version outside of this range to ensure the inclusion of the fix for the authorization issue in the Virtual Network Terminal Server daemon.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2282

Produtos afetados

Opensolaris
Sun Solaris 10