CVE-2009-3706: Medium severity Sun OpenSolaris vulnerability

Published Oct 16, 2009
·
Updated

Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv100 through snv117, allows local users to bypass intended limitations of the filechownself privilege via certain uses of the chown system call.

Affected Software

39 affected components
Sun OpenSolaris=snv_113
Sun OpenSolaris=snv_101
Sun OpenSolaris=snv_104
Sun OpenSolaris=snv_103
Sun OpenSolaris=snv_105
Sun OpenSolaris=snv_114
Sun OpenSolaris=snv_106
Sun OpenSolaris=snv_107
Sun OpenSolaris=snv_112
Sun Solaris=10.0
Sun OpenSolaris=snv_115
Sun OpenSolaris=snv_100
Sun OpenSolaris=snv_111
Sun OpenSolaris=snv_108
Sun OpenSolaris=snv_116
Sun OpenSolaris=snv_117
Sun OpenSolaris=snv_109
Sun OpenSolaris=snv_102
Sun Solaris=10
Sun OpenSolaris=snv_110
Sun OpenSolaris=snv_114
Sun OpenSolaris=snv_110
Sun OpenSolaris=snv_116
Sun OpenSolaris=snv_117
Sun OpenSolaris=snv_103
Sun OpenSolaris=snv_106
Sun OpenSolaris=snv_100
Sun OpenSolaris=snv_112
Sun Solaris=10
Sun OpenSolaris=snv_107
Sun OpenSolaris=snv_115
Sun OpenSolaris=snv_109
Sun OpenSolaris=snv_113
Sun OpenSolaris=snv_102
Sun OpenSolaris=snv_105
Sun OpenSolaris=snv_108
Sun OpenSolaris=snv_104
Sun OpenSolaris=snv_101
Sun OpenSolaris=snv_111

Event History

Oct 16, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-3706?

CVE-2009-3706 is classified as a medium severity vulnerability.

2

How do I fix CVE-2009-3706?

To address CVE-2009-3706, apply the relevant patches provided by Sun Microsystems for affected versions.

3

Which operating systems are affected by CVE-2009-3706?

CVE-2009-3706 affects Sun Solaris 10 and OpenSolaris versions from snv_100 to snv_117.

4

What type of vulnerability is CVE-2009-3706?

CVE-2009-3706 is a local privilege escalation vulnerability affecting file ownership operations.

5

Can CVE-2009-3706 be exploited remotely?

No, CVE-2009-3706 requires local access to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203