First published: Wed May 09 2007(Updated: )
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2529 is rated as a high severity vulnerability due to its potential to cause denial of service and possible privilege escalation.
To fix CVE-2007-2529, apply the latest patches provided by the vendor for Solaris 10 before version 20070507.
CVE-2007-2529 affects local users on Solaris 10 systems prior to the patch release dated May 7, 2007.
CVE-2007-2529 can facilitate denial of service attacks by causing the system to experience a kernel panic.
CVE-2007-2529 does not allow for remote exploitation as it requires local access to the affected system.