First published: Fri Jul 10 2009(Updated: )
Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Solaris | =snv_36 | |
Solaris | =snv_30 | |
Solaris | =snv_26 | |
Solaris | =snv_50 | |
Solaris | =snv_01 | |
Oracle Solaris SPARC | =9 | |
Solaris | =snv_18 | |
Solaris | =snv_53 | |
Solaris | =snv_41 | |
Solaris | =snv_11 | |
Solaris | =snv_39 | |
Solaris | =snv_23 | |
Solaris | =snv_07 | |
Solaris | =snv_55 | |
Solaris | =snv_24 | |
Solaris | =snv_31 | |
Solaris | =snv_04 | |
Solaris | =snv_58 | |
Solaris | =snv_05 | |
Solaris | =snv_17 | |
Solaris | =snv_35 | |
Oracle Solaris SPARC | =8 | |
Solaris | =snv_09 | |
Solaris | =snv_34 | |
Solaris | =snv_44 | |
Solaris | =snv_29 | |
Oracle Solaris SPARC | =10 | |
Solaris | =snv_10 | |
Solaris | =snv_43 | |
Solaris | =snv_48 | |
Solaris | =snv_25 | |
Solaris | =snv_37 | |
Solaris | =snv_40 | |
Solaris | =snv_45 | |
Solaris | =snv_13 | |
Solaris | =snv_06 | |
Solaris | =snv_52 | |
Solaris | =snv_16 | |
Solaris | =snv_46 | |
Solaris | =snv_20 | |
Solaris | =snv_14 | |
Solaris | =snv_57 | |
Solaris | =snv_03 | |
Solaris | =snv_19 | |
Solaris | =snv_21 | |
Solaris | =snv_47 | |
Solaris | =snv_49 | |
Solaris | =snv_15 | |
Solaris | =snv_02 | |
Solaris | =snv_08 | |
Solaris | =snv_28 | |
Solaris | =snv_27 | |
Solaris | =snv_32 | |
Solaris | =snv_56 | |
Solaris | =snv_42 | |
Solaris | =snv_33 | |
Solaris | =snv_22 | |
Solaris | =snv_54 | |
Solaris | =snv_12 | |
Solaris | =snv_38 | |
Solaris | =snv_51 | |
Solaris | =snv_33 | |
Oracle Solaris SPARC | =8 | |
Solaris | =snv_57 | |
Oracle Solaris SPARC | =9 | |
Solaris | =snv_30 | |
Solaris | =snv_27 | |
Solaris | =snv_46 | |
Solaris | =snv_52 | |
Solaris | =snv_05 | |
Solaris | =snv_07 | |
Solaris | =snv_56 | |
Solaris | =snv_43 | |
Solaris | =snv_39 | |
Solaris | =snv_50 | |
Solaris | =snv_31 | |
Solaris | =snv_54 | |
Solaris | =snv_40 | |
Solaris | =snv_49 | |
Solaris | =snv_09 | |
Solaris | =snv_06 | |
Solaris | =snv_37 | |
Solaris | =snv_22 | |
Solaris | =snv_04 | |
Solaris | =snv_13 | |
Solaris | =snv_42 | |
Solaris | =snv_38 | |
Solaris | =snv_36 | |
Solaris | =snv_45 | |
Solaris | =snv_28 | |
Solaris | =snv_08 | |
Solaris | =snv_11 | |
Solaris | =snv_10 | |
Solaris | =snv_48 | |
Solaris | =snv_01 | |
Solaris | =snv_25 | |
Solaris | =snv_18 | |
Solaris | =snv_51 | |
Solaris | =snv_26 | |
Solaris | =snv_16 | |
Solaris | =snv_12 | |
Solaris | =snv_19 | |
Solaris | =snv_32 | |
Solaris | =snv_34 | |
Solaris | =snv_02 | |
Solaris | =snv_21 | |
Solaris | =snv_15 | |
Solaris | =snv_20 | |
Solaris | =snv_55 | |
Solaris | =snv_23 | |
Solaris | =snv_44 | |
Solaris | =snv_53 | |
Solaris | =snv_58 | |
Solaris | =snv_24 | |
Solaris | =snv_41 | |
Oracle Solaris SPARC | =10 | |
Solaris | =snv_47 | |
Solaris | =snv_14 | |
Solaris | =snv_35 | |
Solaris | =snv_17 | |
Solaris | =snv_03 | |
Solaris | =snv_29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2430 has not been assigned a specific severity rating, but it is considered a privilege escalation vulnerability.
To mitigate CVE-2009-2430, it is recommended to restrict RBAC execution profiles for auditconfig or apply available patches from the vendor.
CVE-2009-2430 affects local users on Sun Solaris 8, 9, 10, and OpenSolaris installations with auditing enabled.
CVE-2009-2430 can be exploited through unspecified attack vectors that allow privilege escalation by users with auditconfig access.
Yes, patches addressing CVE-2009-2430 are available from Sun Microsystems or Oracle for the affected Solaris versions.