First published: Thu Jul 16 2009(Updated: )
The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Sun Ray Software | =4.0 | |
Oracle Sun Ray Software | =4.0 | |
Oracle Sun Ray Software | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2491 has a severity rating that indicates it could lead to unauthorized access to user sessions.
To fix CVE-2009-2491, ensure that the Sun Ray Server Software is updated to a patched version provided by Oracle.
CVE-2009-2491 affects local users of Sun Ray Server Software 4.0 when Solaris Trusted Extensions are enabled.
CVE-2009-2491 is a local privilege escalation vulnerability due to resource leaks in the utaudiod daemon.
The primary mitigation for CVE-2009-2491 is to disable the Solaris Trusted Extensions if upgrading is not possible.