CVE Database
/

CVE-2004-1394

Back to search

CVE-2004-1394

Published: Feb 8, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.

VendorProductVersions

n/a

n/a

affected
n/a

References

57453
vendor-advisory
x_refsource_SUNALERT
ESB-2004.0079
third-party-advisory
x_refsource_AUSCERT
10755
third-party-advisory
x_refsource_SECUNIA
1008893
vdb-entry
x_refsource_SECTRACK
3764
vdb-entry
x_refsource_OSVDB
9534
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now