6.3
CVSSv2

CVE-2010-3503

Published: 14/10/2010 Updated: 11/11/2010
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
VMScore: 635
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:N

Vulnerability Summary

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrity via unknown vectors related to su.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle opensolaris

oracle solaris 10

Exploits

From cvsopensolarisorg/source/xref/onnv/onnv-gate/usr/src/cmd/su/suc 521 for (j = 0; initenv[j] != 0; j++) { [1] 522 if (initvar = getenv(initenv[j])) { [2] 535 } else { 536 var = (char *) 537 malloc(strlen(initenv[j]) [3] 538 + strlen(initvar) 539 + 2); 540 ...
Oracle Sun Solaris 10 su NULL point proof of concept exploit ...