CVE

CVE-2009-4211

Severity:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
04/12/2009
Last modified:
10/10/2018

Description

The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sun:solaris:*:*:x86:*:*:*:*:*
cpe:2.3:a:disa:srr_for_solaris:*:*:*:*:*:*:*:*