Lucene search

K
attackerkbAttackerKBAKB:E10C33F9-1459-49B8-8554-7DD499A8313A
HistoryMay 11, 2007 - 12:00 a.m.

CVE-2007-2617

2007-05-1100:00:00
attackerkb.com
11

EPSS

0.481

Percentile

97.5%

srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.

Recent assessments:

h00die at March 25, 2020 12:46am UTC reported:

This is similar to CVE-2009-2936, but on a local binary instead of a network port. The binary, which is obscure and not easy to find, when given an arbitrary file as input with debug and verbose mode set, will attempt to load it. The arbitrary file will fail to load because it isn’t a correct file, and the first line will be echoed back to the screen, split at 20 characters in length. The binary also runs with the suid bit set, so most likely you’ll want /etc/shadow to get root’s hash.

Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 5