CVE-2008-1356 |
|
发布时间 :2008-03-17 13:44:00 | ||
修订时间 :2011-03-07 22:06:57 | ||||
NMCO |
[原文]Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.
[CNNVD]Sun Solaris 10 Java Desktop System GNOME On-Screen Keyboard锁定屏幕绕过漏洞(CNNVD-200803-249)
当运行GNOME On-Screen Keyboard (GOK)时,Sun Solaris 10 Java Desktop System (JDS)的xscreensaver中的未明漏洞。本地用户通过可以引致屏幕保护(screen saver) 崩溃的未知向量,以绕过权限认证。
–
CVSS (基础分值)
CVSS分值: | 6.3 | [中等(MEDIUM)] |
机密性影响: | NONE | [对系统的机密性无影响] |
完整性影响: | COMPLETE | [系统完整性可被完全破坏] |
可用性影响: | COMPLETE | [可能导致系统完全宕机] |
攻击复杂度: | MEDIUM | [漏洞利用存在一定的访问条件] |
攻击向量: | LOCAL | [漏洞利用需要具有物理访问权限或本地帐户] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CWE (弱点类目)
CWE-287 | [认证机制不恰当] |
–
CPE (受影响的平台与产品)
cpe:/o:sun:solaris:10::x86 | |
cpe:/o:sun:solaris:10::sparc |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://sunsolve.sun.com/search/document.do?assetkey=1-26-234661-1 (PATCH) SUNALERT 234661 |
http://xforce.iss.net/xforce/xfdb/41191 (UNKNOWN) XF sun-solaris-xscreensaver-auth-bypass(41191) |
http://www.vupen.com/english/advisories/2008/0875/references (UNKNOWN) VUPEN ADV-2008-0875 |
http://www.securityfocus.com/bid/28243 (UNKNOWN) BID 28243 |
http://secunia.com/advisories/29368 (VENDOR_ADVISORY) SECUNIA 29368 |
http://www.securitytracker.com/id?1019614 (UNKNOWN) SECTRACK 1019614 |
–
漏洞信息
Sun Solaris 10 Java Desktop System GNOME On-Screen Keyboard锁定屏幕绕过漏洞 | |
中危 | 授权问题 |
2008-03-17 00:00:00 | 2008-09-05 00:00:00 |
本地 | |
当运行GNOME On-Screen Keyboard (GOK)时,Sun Solaris 10 Java Desktop System (JDS)的xscreensaver中的未明漏洞。本地用户通过可以引致屏幕保护(screen saver) 崩溃的未知向量,以绕过权限认证。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: http://www.sun.com/software/solaris/ |
–
漏洞信息
42873 |
|
Solaris Java Desktop System (JDS) XscreenSaver Unspecified Authentication Bypass | |
Authentication Management |
|
Loss of Integrity | Patch / RCS |
Vendor Verified |
–
漏洞描述
–
时间线
2008-03-12 |
Unknow |
Unknow | Unknow |
–
解决方案
Currently, there are no known workarounds or upgrades to correct this issue. However, Sun has released a patch to address this vulnerability. |
–
相关参考
|
–
漏洞作者
Unknown or Incomplete |