|
|
>> Sun Cluster Global File System Local Data Disclosure Vulnerability
|
Title : Sun Cluster Global File System Local Data Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-1713 CVE ID : CVE-2008-2539
Rated as : Low Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-06-02
|
A vulnerability has been identified in Sun Cluster for Solaris, which could be exploited by local attackers to bypass security restrictions. This issue is caused by an unspecified error in the Sun Cluster Global File System, which could allow an unprivileged local user to read data from deleted files owned by other users, or cause data integrity issues on certain applications.
Affected Products
Sun Cluster version 3.1 for Solaris
Solution
Sun Cluster 3.1 (for Solaris 8 SPARC) - Apply patch 117950-18 or later
Sun Cluster 3.1 (for Solaris 9 SPARC) - Apply patch 117949-18 or later
Sun Cluster 3.1 (for Solaris 10 SPARC) - Apply patch 120500-02 or later
Sun Cluster 3.1 (for Solaris 9 x86) - Apply patch 117909-18 or later
Sun Cluster 3.1 (for Solaris 10 x86) - Apply patch 120501-02 or later
References
http://www.vupen.com/english/advisories/2008/1713 http://sunsolve.sun.com/search/document.do?assetkey=1-66-201341-1
Credits
Vulnerability reported by the vendor.
ChangeLog
2008-06-02 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|