Back to search
CVE-2004-1394
Published: Feb 8, 2005
Modified: Aug 8, 2024
PUBLISHED
Description
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
solaris-pfexec-gain-privileges(14988)
vdb-entry
x_refsource_XF
57453
vendor-advisory
x_refsource_SUNALERT
ESB-2004.0079
third-party-advisory
x_refsource_AUSCERT
10755
third-party-advisory
x_refsource_SECUNIA
1008893
vdb-entry
x_refsource_SECTRACK
3764
vdb-entry
x_refsource_OSVDB
9534
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now