Vulnerability Name:

CVE-2008-5746 (CCN-47619)

Assigned:2008-12-24
Published:2008-12-24
Updated:2017-08-08
Summary:Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1

This issue can occur in the following releases:

SPARC Platform

* Sun SNMP Management Agent "SUNWmasf" 1.4u2 thru 1.5.4 (For Solaris 8, 9 and 10)

http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1

This issue is addressed in the following release:

SPARC Platform

* Sun SNMP Management Agent ("SUNWmasf") 1.5.5 or later (For Solaris 8, 9 and 10)

Sun SNMP Management Agent is available for download at http://www.sun.com/download/
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
6.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
6.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-59
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2008-5746

Source: OSVDB
Type: UNKNOWN
50987

Source: CCN
Type: SA33328
Sun SNMP Management Agent Insecure Temporary Files

Source: SECUNIA
Type: Vendor Advisory
33328

Source: CCN
Type: SECTRACK ID: 1021496
Sun SNMP Management Agent Temporary File Flaw Lets Local Users Gain Elevated Privileges

Source: SUNALERT
Type: Vendor Advisory
248646

Source: CCN
Type: Sun Alert ID: 248646
Insecure Temporary File Usage Vulnerability in Sun SNMP Management Agent

Source: CCN
Type: ASA-2009-010
Insecure Temporary File Usage Vulnerability in Sun SNMP Management Agent (Sun 248646)

Source: CCN
Type: OSVDB ID: 50987
Sun SNMP Management Agent Unspecified Temporary File Symlink Arbitrary File Overwrite

Source: BID
Type: UNKNOWN
33014

Source: CCN
Type: BID-33014
Sun SNMP Management Agent Insecure Temporary File Creation Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021496

Source: XF
Type: UNKNOWN
snmp-managementagent-symlink(47619)

Source: XF
Type: UNKNOWN
snmp-managementagent-symlink(47619)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:snmp_management_agent:1.4:update_2:sparc:*:*:*:*:*
  • OR cpe:/a:sun:snmp_management_agent:1.5.3:*:sparc:*:*:*:*:*
  • OR cpe:/a:sun:snmp_management_agent:1.5.4:*:sparc:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:8:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9:*:sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10:*:sparc:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:snmp_management_agent:1.5.4::sparc:*:*:*:*:*
  • OR cpe:/a:sun:snmp_management_agent:1.5.3::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun snmp management agent 1.4 update_2
    sun snmp management agent 1.5.3
    sun snmp management agent 1.5.4
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun snmp management agent 1.5.4
    sun snmp management agent 1.5.3