Solaris 10 (sparc) : 148027-03

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.


Synopsis :

The remote host is missing Sun Security Patch number 148027-03

Description :

Vulnerability in the Solaris component of Oracle and Sun Systems
Products Suite (subcomponent: RBAC Configuration). Supported versions
that are affected are 8, 9 and 10. Very difficult to exploit
vulnerability requiring logon to Operating System plus additional,
multiple logins to components. Successful attack of this vulnerability
can escalate attacker privileges resulting in unauthorized Operating
System takeover including arbitrary code execution.

Vulnerability in the Solaris component of Oracle and Sun Systems
Products Suite (subcomponent: Utility/pax). Supported versions that
are affected are 8, 9, 10 and 11. Difficult to exploit vulnerability
requiring logon to Operating System. Successful attack of this
vulnerability can result in unauthorized update, insert or delete
access to some Solaris accessible data and ability to cause a partial
denial of service (partial DOS) of Solaris.

See also :

https://getupdates.oracle.com/readme/148027-03

Solution :

You should install this patch for your system to be up-to-date.

Risk factor :

Medium / CVSS Base Score : 5.9
(CVSS2#AV:L/AC:H/Au:M/C:C/I:C/A:C)

Family: Solaris Local Security Checks

Nessus Plugin ID: 64656 ()

Bugtraq ID:

CVE ID: CVE-2013-0411
CVE-2013-0412

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now