Vulnerability Name: | CVE-2006-2790 (CCN-26899) | ||||||||
Assigned: | 2006-06-02 | ||||||||
Published: | 2006-06-02 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileges. This vulnerability is addressed in the following product release: Sun, Storage Automated Diagnostic Environment, 2.4 (for Solaris 8, 9 and 10) with patch 117654-60 or later. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2790 Source: CCN Type: SA20445 Sun StorADE Privilege Escalation Vulnerability Source: SECUNIA Type: UNKNOWN 20445 Source: CCN Type: SECTRACK ID: 1016215 Sun StorADE Unsafe File Permissions Let Local Users Gain Root Privileges Source: SECTRACK Type: UNKNOWN 1016215 Source: CCN Type: Sun Alert ID: 102305 Security Vulnerability With Sun StorADE Version 2.4 Installation Source: SUNALERT Type: Patch, Vendor Advisory 102305 Source: CCN Type: OSVDB ID: 25972 Sun StorADE Permission Weakness Local Privilege Escalation Source: BID Type: UNKNOWN 18266 Source: CCN Type: BID-18266 Sun StorADE Local Privilege Escalation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2139 Source: XF Type: UNKNOWN sun-storade-code-execution(26899) Source: XF Type: UNKNOWN sun-storade-code-execution(26899) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |