CVE-2008-2538

Current Description

Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.

Basic Data

PublishedJune 03, 2008
Last ModifiedSeptember 29, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-362
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:M/Au:N/C:C/I:C/A:C
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score6.9
SeverityMEDIUM
Exploitability Score3.4
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3OSSunSolaris8*sparc*****
    2.3OSSunSolaris8*x86*****
    2.3OSSunSolaris9*sparc*****
    2.3OSSunSolaris9*x86*****
    2.3OSSunSolaris10*sparc*****
    2.3OSSunSolaris10*x86*****

Vulnerable Software List

VendorProductVersions
Sun Solaris 10, 8, 9

References

NameSourceURLTags
30482http://secunia.com/advisories/30482SECUNIAVendor Advisory
30542http://secunia.com/advisories/30542SECUNIAVendor Advisory
1020151http://securitytracker.com/id?1020151SECTRACK
237864http://sunsolve.sun.com/search/document.do?assetkey=1-26-237864-1SUNALERT
http://support.avaya.com/elmodocs2/security/ASA-2008-222.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-222.htmCONFIRM
ADV-2008-1714http://www.vupen.com/english/advisories/2008/1714VUPEN
solaris-crontab-code-execution(42763)https://exchange.xforce.ibmcloud.com/vulnerabilities/42763XF
oval:org.mitre.oval:def:4725https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4725OVAL