9.3
CVSSv2

CVE-2009-4211

Published: 04/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.

Vulnerable Product Search on Vulmon Subscribe to Product

disa srr_for_solaris

Exploits

Running DISA SRR scripts against your server can get you easily rooted They run arbitrary binaries discovered on the filesystem as root They apparently need another Security Readiness Review script to first audit their own Security Readiness Review scripts This is an update to the previous finding, documenting that although a fix was attempted, ...