Vulnerabilities > CVE-2015-2616 - Local Security vulnerability in Oracle and SUN Systems Product Suite 3.3/4.2

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
local
low complexity
oracle
nessus

Summary

Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.

Vulnerable Configurations

Part Description Count
Application
Oracle
2

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_145334.NASL
    descriptionVulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: System management). Supported versions that are affected are 3.3 and 4.1. Easily exploitable vulnerability allows successful authenticated network attacks via TCP/IP. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution. Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: System management). Supported versions that are affected are 3.3 and 4.1. Easily exploitable vulnerability requiring logon to Operating System plus additional, multiple logins to components. Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System takeover including arbitrary code execution. This plugin has been deprecated and either replaced with individual 145334 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id71706
    published2013-12-28
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=71706
    titleSolaris 10 (x86) : 145334-39 (deprecated)
    code
    
    #
    # (C) Tenable Network Security, Inc.
    #
    # @DEPRECATED@
    #
    # Disabled on 2018/03/12. Deprecated and either replaced by
    # individual patch-revision plugins, or has been deemed a
    # non-security advisory.
    #
    include("compat.inc");
    
    if (description)
    {
      script_id(71706);
      script_version("1.22");
      script_cvs_date("Date: 2018/07/30 13:40:15");
    
      script_cve_id("CVE-2014-4259", "CVE-2014-6480", "CVE-2015-2616");
    
      script_name(english:"Solaris 10 (x86) : 145334-39 (deprecated)");
      script_summary(english:"Check for patch 145334-39");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"This plugin has been deprecated."
      );
      script_set_attribute(
        attribute:"description",
        value:
    "Vulnerability in the Solaris Cluster component of Oracle Sun Systems
    Products Suite (subcomponent: System management). Supported versions
    that are affected are 3.3 and 4.1. Easily exploitable vulnerability
    allows successful authenticated network attacks via TCP/IP. Successful
    attack of this vulnerability can result in unauthorized Operating
    System takeover including arbitrary code execution.
    
    Vulnerability in the Solaris Cluster component of Oracle Sun Systems
    Products Suite (subcomponent: System management). Supported versions
    that are affected are 3.3 and 4.1. Easily exploitable vulnerability
    requiring logon to Operating System plus additional, multiple logins
    to components. Successful attack of this vulnerability can escalate
    attacker privileges resulting in unauthorized Operating System
    takeover including arbitrary code execution.
    
    This plugin has been deprecated and either replaced with individual
    145334 patch-revision plugins, or deemed non-security related."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://getupdates.oracle.com/readme/145334-39"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"n/a"
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:sun:solaris");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2018/01/08");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/12/28");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2013-2018 Tenable Network Security, Inc.");
      script_family(english:"Solaris Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/Solaris/showrev");
    
      exit(0);
    }
    
    exit(0, "This plugin has been deprecated. Consult specific patch-revision plugins for patch 145334 instead.");
    
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_145333.NASL
    descriptionVulnerability in the Solaris Cluster component of Oracle and Sun Systems Products Suite (subcomponent: Zone Cluster Infrastructure). Supported versions that are affected are 3.2, 3.3 and 4 prior to 4.1 SRU 3. Easily exploitable vulnerability requiring logon to Operating System. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution. This plugin has been deprecated and either replaced with individual 145333 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id71659
    published2013-12-28
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=71659
    titleSolaris 10 (sparc) : 145333-39 (deprecated)
    code
    
    #
    # (C) Tenable Network Security, Inc.
    #
    # @DEPRECATED@
    #
    # Disabled on 2018/03/12. Deprecated and either replaced by
    # individual patch-revision plugins, or has been deemed a
    # non-security advisory.
    #
    include("compat.inc");
    
    if (description)
    {
      script_id(71659);
      script_version("1.22");
      script_cvs_date("Date: 2018/07/30 13:40:15");
    
      script_cve_id("CVE-2013-3746", "CVE-2015-2616");
    
      script_name(english:"Solaris 10 (sparc) : 145333-39 (deprecated)");
      script_summary(english:"Check for patch 145333-39");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"This plugin has been deprecated."
      );
      script_set_attribute(
        attribute:"description",
        value:
    "Vulnerability in the Solaris Cluster component of Oracle and Sun
    Systems Products Suite (subcomponent: Zone Cluster Infrastructure).
    Supported versions that are affected are 3.2, 3.3 and 4 prior to 4.1
    SRU 3. Easily exploitable vulnerability requiring logon to Operating
    System. Successful attack of this vulnerability can result in
    unauthorized Operating System takeover including arbitrary code
    execution.
    
    This plugin has been deprecated and either replaced with individual
    145333 patch-revision plugins, or deemed non-security related."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://getupdates.oracle.com/readme/145333-39"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"n/a"
      );
      script_set_cvss_base_vector("CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:sun:solaris");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2018/01/08");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/12/28");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2013-2018 Tenable Network Security, Inc.");
      script_family(english:"Solaris Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/Solaris/showrev");
    
      exit(0);
    }
    
    exit(0, "This plugin has been deprecated. Consult specific patch-revision plugins for patch 145333 instead.");