CVE-2009-0873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
11/03/2009
Last modified:
09/04/2025

Description

The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sun:opensolaris:snv_01:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_02:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_03:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_04:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_05:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_06:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_07:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_08:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_09:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_10:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_20:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_21:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_22:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_23:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_24:*:sparc:*:*:*:*:*