Vulnerability Name:

CVE-2003-0027 (CCN-11129)

Assigned:2003-01-22
Published:2003-01-22
Updated:2018-10-30
Summary:Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2003-0027

Source: BUGTRAQ
Type: UNKNOWN
20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner

Source: CCN
Type: Sun Alert ID: 50104
Security Issue with kcms_server Daemon

Source: SUNALERT
Type: UNKNOWN
50104

Source: CCN
Type: CIAC Information Bulletin O-069
Sun kcms_server Daemon Vulnerability

Source: CCN
Type: Entercept Security Alert 01/22/2003
KCMS Library Service Daemon Arbitrary File Retrieval Vulnerability

Source: MISC
Type: Patch, Vendor Advisory
http://www.entercept.com/news/uspr/01-22-03.asp

Source: CCN
Type: US-CERT VU#850785
Sun KCMS library service daemon does not adequately validate location of KCMS profiles

Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#850785

Source: CCN
Type: OSVDB ID: 8201
Sun Kodak Color Management System (KCMS) kcms_server Arbitrary File Access

Source: BID
Type: UNKNOWN
6665

Source: CCN
Type: BID-6665
Kodak KCMS KCS_OPEN_PROFILE Procedure Arbitrary File Access Vulnerability

Source: XF
Type: UNKNOWN
solaris-kcms-directory-traversal(11129)

Source: XF
Type: UNKNOWN
solaris-kcms-directory-traversal(11129)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:120

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:195

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:2592

Source: CCN
Type: Rapid7 Vulnerability & Exploit Database
Solaris KCMS + TTDB Arbitrary File Read

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sun:solaris:2.5.1:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.6:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:7.0:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8.0:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9.0:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9.0:x86_update_2:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:-:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.7:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.8:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sun:sunos:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.6:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.8:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.9:*:*:*:*:*:*:*
  • OR cpe:/o:sun:sunos:5.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:2592
    V
    KCMS KCS_OPEN_PROFILE File Disclosure Vulnerability
    2010-09-20
    BACK
    sun solaris 2.5.1
    sun solaris 2.6
    sun solaris 7.0
    sun solaris 8.0
    sun solaris 9.0
    sun solaris 9.0 x86_update_2
    sun sunos -
    sun sunos 5.5.1
    sun sunos 5.7
    sun sunos 5.8
    sun solaris 2.5.1
    sun solaris 2.6
    sun solaris 8
    sun solaris 9
    sun solaris 7.0