Vulnerability Name: | CVE-2009-3468 (CCN-53461) | ||||||||
Assigned: | 2009-09-23 | ||||||||
Published: | 2009-09-23 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3468 Source: OSVDB Type: UNKNOWN 58319 Source: CCN Type: SA36822 Sun Solaris Trusted Extensions Common Desktop Environment Vulnerability Source: SECUNIA Type: Vendor Advisory 36822 Source: CCN Type: SECTRACK ID: 1022943 Solaris Trusted Extensions Common Desktop Environment Lets Local Users Gain Elevated Privileges Source: CONFIRM Type: Patch http://sunsolve.sun.com/search/document.do?assetkey=1-21-126365-15-1 Source: CONFIRM Type: Patch http://sunsolve.sun.com/search/document.do?assetkey=1-21-139620-01-1 Source: CCN Type: Sun Alert ID: 267488 Security Vulnerabilities in Solaris Trusted Extensions Common Desktop Environment (CDE) may allow Privilege Escalation or Mandatory Access Control (MAC) Policy Violation Source: SUNALERT Type: Vendor Advisory 267488 Source: CCN Type: OSVDB ID: 58319 Solaris Trusted Extensions Common Desktop Environment (CDE) Unspecified Local Privilege Escalation Source: BID Type: UNKNOWN 36510 Source: CCN Type: BID-36510 Sun Solaris Trusted Extensions Common Desktop Environment Local Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1022943 Source: VUPEN Type: Vendor Advisory ADV-2009-2756 Source: XF Type: UNKNOWN cde-mac-priv-escalation(53461) Source: XF Type: UNKNOWN cde-mac-priv-escalation(53461) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |