LOW · 2.1

CVE-2007-2617

srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of ...

Vulnerability Description

srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SunSolaris10.0
SunNet Connect Software3.2.3

References

FAQ

What is CVE-2007-2617?

CVE-2007-2617 is a vulnerability with a CVSS score of 2.1 (LOW). srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of ...

How severe is CVE-2007-2617?

CVE-2007-2617 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2617?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris, Sun Net Connect Software.