Vulnerability Name: | CVE-2008-5746 (CCN-47619) | ||||||||
Assigned: | 2008-12-24 | ||||||||
Published: | 2008-12-24 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files. http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1 This issue can occur in the following releases: SPARC Platform * Sun SNMP Management Agent "SUNWmasf" 1.4u2 thru 1.5.4 (For Solaris 8, 9 and 10) http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1 This issue is addressed in the following release: SPARC Platform * Sun SNMP Management Agent ("SUNWmasf") 1.5.5 or later (For Solaris 8, 9 and 10) Sun SNMP Management Agent is available for download at http://www.sun.com/download/ | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 6.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-59 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5746 Source: OSVDB Type: UNKNOWN 50987 Source: CCN Type: SA33328 Sun SNMP Management Agent Insecure Temporary Files Source: SECUNIA Type: Vendor Advisory 33328 Source: CCN Type: SECTRACK ID: 1021496 Sun SNMP Management Agent Temporary File Flaw Lets Local Users Gain Elevated Privileges Source: SUNALERT Type: Vendor Advisory 248646 Source: CCN Type: Sun Alert ID: 248646 Insecure Temporary File Usage Vulnerability in Sun SNMP Management Agent Source: CCN Type: ASA-2009-010 Insecure Temporary File Usage Vulnerability in Sun SNMP Management Agent (Sun 248646) Source: CCN Type: OSVDB ID: 50987 Sun SNMP Management Agent Unspecified Temporary File Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 33014 Source: CCN Type: BID-33014 Sun SNMP Management Agent Insecure Temporary File Creation Vulnerability Source: SECTRACK Type: UNKNOWN 1021496 Source: XF Type: UNKNOWN snmp-managementagent-symlink(47619) Source: XF Type: UNKNOWN snmp-managementagent-symlink(47619) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |