Vulnerability Name: | CVE-2007-2529 (CCN-34147) | ||||||||
Assigned: | 2007-05-07 | ||||||||
Published: | 2007-05-07 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL. | ||||||||
CVSS v3 Severity: | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-2529 Source: IDEFENSE Type: Vendor Advisory 20070507 Sun Microsystems Solaris ACE_SETACL Integer Signedness DoS Vulnerability Source: OSVDB Type: UNKNOWN 34906 Source: CCN Type: SA25162 Sun Solaris "acl()" Local Denial of Service Source: SECUNIA Type: Patch, Vendor Advisory 25162 Source: CCN Type: SECTRACK ID: 1018009 Solaris facl() Integer Error Lets Local Users Deny Service Source: SECTRACK Type: UNKNOWN 1018009 Source: CCN Type: Sun Alert ID: 102869 Security Vulnerability Relating to the acl(2) System Call May Allow Denial of Service (DoS) to the System Source: SUNALERT Type: Patch, Vendor Advisory 102869 Source: CCN Type: ASA-2007-243 Security Vulnerability Relating to the acl(2) System Call May Allow Denial of Service (DoS) to the System (Sun 102869) Source: CCN Type: OSVDB ID: 34906 Solaris acl() System Call Local Overflow Source: BID Type: Patch 23863 Source: CCN Type: BID-23863 Sun Solaris ACE_SETACL Local Denial Of Service Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-1683 Source: XF Type: UNKNOWN solaris-acl-system-dos(34147) Source: XF Type: UNKNOWN solaris-acl-system-dos(34147) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 05.07.07 Sun Microsystems Solaris ACE_SETACL Integer Signedness DoS Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1669 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |