CVE-2009-0873
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as…
Does this matter?
Lower severity and a low EPSS score (1.96%). Track it; it rarely justifies an emergency change on its own.
Description
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/opensolaris · sun/sunos · sun/solaris
- Source
- cve@mitre.org
References
- http://osvdb.org/52560
- http://secunia.com/advisories/34225Vendor Advisory
- http://secunia.com/advisories/34435
- http://securitytracker.com/id?1021832Exploit
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-250306-1Patch, Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-096.htm
- http://www.securityfocus.com/bid/34062Exploit
- http://www.vupen.com/english/advisories/2009/0657Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0814
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49171
- http://osvdb.org/52560
- http://secunia.com/advisories/34225Vendor Advisory
- http://secunia.com/advisories/34435
- http://securitytracker.com/id?1021832Exploit
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-250306-1Patch, Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-096.htm
- http://www.securityfocus.com/bid/34062Exploit
- http://www.vupen.com/english/advisories/2009/0657Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0814
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49171
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.