Vulnerability Name:

CVE-2007-3471 (CCN-35127)

Assigned:2007-06-27
Published:2007-06-27
Updated:2017-09-29
Summary:Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-3471

Source: OSVDB
Type: UNKNOWN
36608

Source: CCN
Type: SA25876
Sun Solaris dtsession Privilege Escalation Vulnerability

Source: SECUNIA
Type: Vendor Advisory
25876

Source: CCN
Type: SA26136
Avaya CMS / IR Solaris dtsession Privilege Escalation Vulnerability

Source: SECUNIA
Type: UNKNOWN
26136

Source: CCN
Type: Sun Alert ID: 102954
dtsession(1X) Contains a Buffer Overflow Vulnerability

Source: SUNALERT
Type: Patch
102954

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2007-310.htm

Source: CCN
Type: ASA-2007-310
dtsession(1X) Contains a Buffer Overflow Vulnerability (Sun 102954)

Source: CCN
Type: OSVDB ID: 36608
Solaris Common Desktop Environment (CDE) Session Manager dtsession Local Overflow

Source: BID
Type: UNKNOWN
24687

Source: CCN
Type: BID-24687
Sun Solaris Dtsession Local Buffer Overflow Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2007-2369

Source: XF
Type: UNKNOWN
solaris-dtsession1x-bo(35127)

Source: XF
Type: UNKNOWN
solaris-dtsession1x-bo(35127)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:2015

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sun:solaris:8.0:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8.0:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9.0:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9.0:*:x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10.0:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10.0:*:x86:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*
  • AND
  • cpe:/a:avaya:interactive_response:1.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:2015
    V
    dtsession(1X) Contains a Buffer Overflow Vulnerability
    2007-08-02
    BACK
    sun solaris 8.0
    sun solaris 8.0
    sun solaris 9.0
    sun solaris 9.0
    sun solaris 10.0
    sun solaris 10.0
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 9
    avaya interactive response 1.3