First published: Mon Feb 07 2011(Updated: )
Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Sun Microsystems Sunscreen Firewall | ||
Sun SunOS | =5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0902 is considered a critical vulnerability due to its potential for local users to execute arbitrary code.
To fix CVE-2011-0902, ensure that untrusted paths are not included in the PATH or LD_LIBRARY_PATH environment variables for the Java Service.
CVE-2011-0902 affects the Sun Microsystems SunScreen Firewall on SunOS 5.9.
CVE-2011-0902 is a local vulnerability and cannot be exploited remotely.
The responsibility for addressing CVE-2011-0902 lies with the system administrators of affected environments.