Vulnerabilities > CVE-2011-0902 - Local Privilege Escalation vulnerability in Sun SunScreen Firewall

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
oracle
sun
exploit available

Summary

Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable. Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'

Vulnerable Configurations

Part Description Count
Hardware
Oracle
1
OS
Sun
1

Exploit-Db

descriptionSun Microsystems SunScreen Firewall Root Exploit. CVE-2011-0902. Remote exploits for multiple platform
fileexploits/multiple/remote/16041.txt
idEDB-ID:16041
last seen2016-02-01
modified2011-01-25
platformmultiple
port
published2011-01-25
reporterkingcope
sourcehttps://www.exploit-db.com/download/16041/
titleSun Microsystems SunScreen Firewall Root Exploit
typeremote