CWE
264 862
Advisory Published
Updated

CVE-2009-2282

First published: Wed Jul 01 2009(Updated: )

The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.

Credit: cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Solaris>=snv_41<=snv_108
Oracle Solaris SPARC=10
Solaris=snv_101
Solaris=snv_57
Solaris=snv_87
Solaris=snv_73
Solaris=snv_91
Solaris=snv_85
Solaris=snv_74
Solaris=snv_104
Solaris=snv_103
Solaris=snv_66
Solaris=snv_105
Solaris=snv_46
Solaris=snv_52
Solaris=snv_82
Solaris=snv_72
Solaris=snv_88
Solaris=snv_56
Solaris=snv_43
Solaris=snv_50
Solaris=snv_93
Solaris=snv_54
Solaris=snv_40
Solaris=snv_65
Solaris=snv_49
Solaris=snv_106
Solaris=snv_107
Solaris=snv_71
Solaris=snv_64
Solaris=snv_77
Solaris=snv_61
Solaris=snv_79
Solaris=snv_42
Solaris=snv_90
Solaris=snv_70
Solaris=snv_45
Solaris=snv_59
Solaris=snv_48
Solaris=snv_97
Solaris=snv_51
Solaris=snv_83
Solaris=snv_100
Solaris=snv_96
Solaris=snv_81
Solaris=snv_94
Solaris=snv_86
Solaris=snv_98
Solaris=snv_80
Solaris=snv_68
Solaris=snv_67
Solaris=snv_95
Solaris=snv_108
Solaris=snv_78
Solaris=snv_76
Solaris=snv_55
Solaris=snv_69
Solaris=snv_84
Solaris=snv_44
Solaris=snv_60
Solaris=snv_92
Solaris=snv_63
Solaris=snv_53
Solaris=snv_58
Solaris=snv_99
Solaris=snv_75
Solaris=snv_102
Solaris=snv_41
Oracle Solaris SPARC=10
Solaris=snv_47
Solaris=snv_62
Solaris=snv_89

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2009-2282?

    CVE-2009-2282 has been rated as a medium severity vulnerability.

  • How do I fix CVE-2009-2282?

    To fix CVE-2009-2282, users should upgrade to the latest version of Solaris that addresses this vulnerability.

  • What platforms are affected by CVE-2009-2282?

    CVE-2009-2282 affects Sun Solaris 10 and OpenSolaris on SPARC platforms.

  • What type of vulnerability is CVE-2009-2282?

    CVE-2009-2282 is an authorization vulnerability related to guest console access in the Virtual Network Terminal Server daemon.

  • Could CVE-2009-2282 allow unauthorized access to systems?

    Yes, CVE-2009-2282 allows local control-domain users to gain unauthorized guest-domain privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203