First published: Fri Oct 05 2007(Updated: )
Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.8 | |
Sun SunOS | =5.10 | |
Sun SunOS | =5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5225 is rated as medium severity due to its potential to expose sensitive memory contents.
Fixing CVE-2007-5225 requires applying security patches provided by Sun Microsystems for affected versions of SunOS.
Local users on Sun Solaris 8 through 10 are affected by CVE-2007-5225.
The vulnerable systems include Sun Solaris versions 5.8, 5.9, and 5.10.
CVE-2007-5225 can facilitate a local privilege escalation attack by allowing users to access restricted memory regions.