Vulnerability Description
The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Opensolaris | >= snv_41, <= snv_108 |
| Oracle | Solaris | 10 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/35547Broken LinkVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141778-01-1Broken LinkPatch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-262708-1Broken LinkPatchVendor Advisory
- http://www.osvdb.org/55329Broken Link
- http://www.securityfocus.com/bid/35502Broken LinkThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/35547Broken LinkVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141778-01-1Broken LinkPatch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-262708-1Broken LinkPatchVendor Advisory
- http://www.osvdb.org/55329Broken Link
- http://www.securityfocus.com/bid/35502Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2009-2282?
CVE-2009-2282 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest ...
How severe is CVE-2009-2282?
CVE-2009-2282 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2282?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Opensolaris, Oracle Solaris.