CVE-2009-0872: Medium severity Sun OpenSolaris vulnerability
The NFS server in Sun Solaris 10, and OpenSolaris before snv111, does not properly implement the AUTHNONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTHNONE and AUTHSYS security modes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSolaristo a version that resolves this vulnerability.Fixed in snv_111
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0872?
CVE-2009-0872 is classified as a high-severity vulnerability due to its potential to allow remote attackers to bypass access restrictions.
How do I fix CVE-2009-0872?
To fix CVE-2009-0872, update to a patched version of Solaris or OpenSolaris that addresses this vulnerability.
What software is affected by CVE-2009-0872?
CVE-2009-0872 affects various versions of Sun Solaris 10 and OpenSolaris prior to snv_111.
What type of vulnerability is CVE-2009-0872?
CVE-2009-0872 is a vulnerability related to improper implementation of the AUTH_NONE security mode in the NFS server.
Can CVE-2009-0872 lead to unauthorized data access?
Yes, CVE-2009-0872 can allow unauthorized remote access to read or modify files due to the security flaw.