CVE-2007-2617
Sun Microsystems Solaris SRSEXEC 3.2.x - Arbitrary File Read Local Information Disclosure
Severity Score
2.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.
srsexec en el paquete Sun Remote Services (SRS) Net Connect Software Proxy Core en Sun Solaris 10 no hace cumplir los permisos de ficheros al abrirlos, lo cual permite a usuarios locales leer la primera línea de ficheros de su elección mediante las opciones -d y -v.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-05-10 First Exploit
- 2007-05-11 CVE Reserved
- 2007-05-11 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (12)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30021 | 2007-05-10 |
URL | Date | SRC |
---|---|---|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102891-1 | 2017-10-11 | |
http://www.securityfocus.com/bid/23915 | 2017-10-11 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25194 | 2017-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sun Search vendor "Sun" | Net Connect Software Search vendor "Sun" for product "Net Connect Software" | 3.2.3 Search vendor "Sun" for product "Net Connect Software" and version "3.2.3" | - |
Affected
| in | Sun Search vendor "Sun" | Solaris Search vendor "Sun" for product "Solaris" | 10.0 Search vendor "Sun" for product "Solaris" and version "10.0" | sparc |
Safe
|
Sun Search vendor "Sun" | Net Connect Software Search vendor "Sun" for product "Net Connect Software" | 3.2.4 Search vendor "Sun" for product "Net Connect Software" and version "3.2.4" | - |
Affected
| in | Sun Search vendor "Sun" | Solaris Search vendor "Sun" for product "Solaris" | 10.0 Search vendor "Sun" for product "Solaris" and version "10.0" | sparc |
Safe
|