Oval Definition:
oval:org.mitre.oval:def:943
Revision Date
:
2007-03-21
Version
:
19
Title
:
Solaris Xsun and Xprt Unspecified Local Privilege Escalation
Description
:
Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2005-3099
Platform(s)
:
Sun Solaris 10
Sun Solaris 7
Sun Solaris 8
Sun Solaris 9
Product(s)
:
Xsun
Definition Synopsis
Software section
Solaris 7 Installed
OR
Solaris 8 (SPARC) meets Sun Alert ID 101800 criteria.
Solaris 8 Installed
AND
sparc architecture
AND
NOT
Patch 108652-93 or later installed
OR
Solaris 8 (x86) meets Sun Alert ID 101800 criteria.
Solaris 8 Installed
AND
ix86 architecture
AND
NOT
Patch 108653-82 or later installed
OR
Solaris 9 (SPARC) meets Sun Alert ID 101800 criteria.
Solaris 9 Installed
AND
sparc architecture
AND
NOT
Patch 112785-50 or later installed
OR
Solaris 9 (x86) meets Sun Alert ID 101800 criteria.
Solaris 9 Installed
AND
ix86 architecture
AND
NOT
Patch 112786-39 or later installed
OR
Solaris 10 (SPARC) meets Sun Alert ID 101800 criteria.
Solaris 10 Installed
AND
sparc architecture
AND
NOT
Patch 119059-05 or later installed
OR
Solaris 10 (x86) meets Sun Alert ID 101800 criteria.
Solaris 10 Installed
AND
ix86 architecture
AND
NOT
Patch 119060-05 or later installed
AND
Configuration section
File Xsun is SUID|SGID AND Executable
File Xsun SUID|SGID
File Xsun SUID
OR
File Xprt SUID
AND
File Xsun SGID and executable
OR
File Xprt is SUID|SGID AND Executable
File Xprt SUID|SGID
File Xsun SUID
OR
File Xprt SUID
AND
File Xsun SGID and executable
BACK