Vulnerability Description
The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Ray Server Software | 4.0 |
References
- http://osvdb.org/55978
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-127553-06-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253889-1PatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1915
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51742
- http://osvdb.org/55978
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-127553-06-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253889-1PatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1915
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51742
FAQ
What is CVE-2009-2491?
CVE-2009-2491 is a vulnerability with a CVSS score of 4.4 (MEDIUM). The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "reso...
How severe is CVE-2009-2491?
CVE-2009-2491 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2491?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Ray Server Software.