CVE-2009-0873

medium

Description

The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/49171

http://www.vupen.com/english/advisories/2009/0814

http://www.vupen.com/english/advisories/2009/0657

http://support.avaya.com/elmodocs2/security/ASA-2009-096.htm

http://sunsolve.sun.com/search/document.do?assetkey=1-66-250306-1

http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1

http://secunia.com/advisories/34435

http://secunia.com/advisories/34225

http://osvdb.org/52560

Details

Source: Mitre, NVD

Published: 2009-03-11

Updated: 2018-10-30

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium