Vulnerability Name: | CVE-2007-5225 (CCN-36918) | ||||||||
Assigned: | 2007-10-02 | ||||||||
Published: | 2007-10-02 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:F/RL:OF/RC:C)
1.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-189 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5225 Source: IDEFENSE Type: UNKNOWN 20071002 Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability Source: CCN Type: SA27024 Sun Solaris FIFO File System Unauthorized Data Access Source: SECUNIA Type: Vendor Advisory 27024 Source: CCN Type: SA27654 Avaya CMS / IR Sun Solaris FIFO File System Unauthorized Data Access Source: SECUNIA Type: Vendor Advisory 27654 Source: CCN Type: SECTRACK ID: 1018766 Solaris Named Pipes Bug Discloses Kernel Memory to Local Users Source: CCN Type: Sun Alert ID: 103061 Security Vulnerability in Solaris Named Pipes (pipe(2)) May Allow Unauthorized Data Access Source: SUNALERT Type: UNKNOWN 103061 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2007-463.htm Source: CCN Type: ASA-2007-463 Security Vulnerability in Solaris Named Pipes (pipe(2)) May Allow Unauthorized Data Access (Sun 103061) Source: CCN Type: OSVDB ID: 37714 Solaris FIFO (Named Pipes) I_PEEK ioctl Arbitrary Memory Disclosure Source: BUGTRAQ Type: UNKNOWN 20071004 Re: iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability Source: BID Type: UNKNOWN 25905 Source: CCN Type: BID-25905 Sun Solaris I_PEEK IOCTL Handler Local Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1018766 Source: VUPEN Type: Vendor Advisory ADV-2007-3339 Source: CCN Type: Oracle Web site Article ID: 1000506.1 Source: XF Type: UNKNOWN solaris-namedpipes-information-disclosure(36918) Source: XF Type: UNKNOWN solaris-namedpipes-information-disclosure(36918) Source: CCN Type: 0xdea exploits GIT Repository raptor_peek.c Source: CCN Type: iDefense PUBLIC ADVISORY: 10.02.07 Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2170 Source: CCN Type: Packet Storm Security [10-11-2007] solaris-fifofs.txt Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [2007-10-10] Source: EXPLOIT-DB Type: UNKNOWN 4516 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [2008-03-10] Source: EXPLOIT-DB Type: UNKNOWN 5227 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |