The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2009-03-11 07:19
Updated : 2018-10-30 09:25
NVD link : CVE-2009-0873
Mitre link : CVE-2009-0873
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
sun
- solaris
- opensolaris
- sunos