Sun Solaris Text Editors Command Execution Vulnerability
BID:31229
Info
Sun Solaris Text Editors Command Execution Vulnerability
| Bugtraq ID: | 31229 |
| Class: | Design Error |
| CVE: |
CVE-2008-4131 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2008 12:00AM |
| Updated: | Oct 03 2008 04:38PM |
| Credit: | Eli the Bearded |
| Vulnerable: |
Sun Solaris 9_x86 Update 2 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 14.1 Avaya CMS Server 14.0 Avaya CMS Server 13.1 |
| Not Vulnerable: | |
Discussion
Sun Solaris Text Editors Command Execution Vulnerability
Sun Solaris text editors are prone to a command-execution vulnerability.
An attacker may leverage this issue to execute arbitrary commands with the privileges of another user on the affected computer.
Sun Solaris 8, 9, and 10 are affected.
Sun Solaris text editors are prone to a command-execution vulnerability.
An attacker may leverage this issue to execute arbitrary commands with the privileges of another user on the affected computer.
Sun Solaris 8, 9, and 10 are affected.
Exploit / POC
Sun Solaris Text Editors Command Execution Vulnerability
The following example is available:
The following example is available:
Solution / Fix
Sun Solaris Text Editors Command Execution Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Sun Solaris Text Editors Command Execution Vulnerability
References:
References: