CVE-2009-2296

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/07/2009
Last modified:
09/04/2025

Description

The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sun:opensolaris:*:*:sparc:*:*:*:*:* snv_95 (including)
cpe:2.3:o:sun:opensolaris:*:*:x86:*:*:*:*:* snv_95 (including)
cpe:2.3:o:sun:opensolaris:*:*:sparc:*:*:*:*:* snv_118 (including)
cpe:2.3:o:sun:opensolaris:*:*:x86:*:*:*:*:* snv_118 (including)
cpe:2.3:o:sun:opensolaris:snv_01:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_01:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_02:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_02:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_03:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_03:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_04:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_04:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_05:*:sparc:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_05:*:x86:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_06:*:sparc:*:*:*:*:*