CVE-2008-2539
The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/cluster
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30483Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-201341-1
- http://www.securityfocus.com/bid/29458
- http://www.securitytracker.com/id?1020152
- http://www.vupen.com/english/advisories/2008/1713
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42762
- http://secunia.com/advisories/30483Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-201341-1
- http://www.securityfocus.com/bid/29458
- http://www.securitytracker.com/id?1020152
- http://www.vupen.com/english/advisories/2008/1713
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42762
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.