| CVE-2008-1356 |
|
发布时间 :2008-03-17 13:44:00 | ||
| 修订时间 :2011-03-07 22:06:57 | ||||
| NMCO |
[原文]Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.
[CNNVD]Sun Solaris 10 Java Desktop System GNOME On-Screen Keyboard锁定屏幕绕过漏洞(CNNVD-200803-249)
当运行GNOME On-Screen Keyboard (GOK)时,Sun Solaris 10 Java Desktop System (JDS)的xscreensaver中的未明漏洞。本地用户通过可以引致屏幕保护(screen saver) 崩溃的未知向量,以绕过权限认证。
–
CVSS (基础分值)
| CVSS分值: | 6.3 | [中等(MEDIUM)] |
| 机密性影响: | NONE | [对系统的机密性无影响] |
| 完整性影响: | COMPLETE | [系统完整性可被完全破坏] |
| 可用性影响: | COMPLETE | [可能导致系统完全宕机] |
| 攻击复杂度: | MEDIUM | [漏洞利用存在一定的访问条件] |
| 攻击向量: | LOCAL | [漏洞利用需要具有物理访问权限或本地帐户] |
| 身份认证: | NONE | [漏洞利用无需身份认证] |
–
CWE (弱点类目)
| CWE-287 | [认证机制不恰当] |
–
CPE (受影响的平台与产品)
| cpe:/o:sun:solaris:10::x86 | |
| cpe:/o:sun:solaris:10::sparc |
–
OVAL (用于检测的技术细节)
| 未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-234661-1 (PATCH) SUNALERT 234661 |
|
http://xforce.iss.net/xforce/xfdb/41191 (UNKNOWN) XF sun-solaris-xscreensaver-auth-bypass(41191) |
|
http://www.vupen.com/english/advisories/2008/0875/references (UNKNOWN) VUPEN ADV-2008-0875 |
|
http://www.securityfocus.com/bid/28243 (UNKNOWN) BID 28243 |
|
http://secunia.com/advisories/29368 (VENDOR_ADVISORY) SECUNIA 29368 |
|
http://www.securitytracker.com/id?1019614 (UNKNOWN) SECTRACK 1019614 |
–
漏洞信息
| Sun Solaris 10 Java Desktop System GNOME On-Screen Keyboard锁定屏幕绕过漏洞 | |
| 中危 | 授权问题 |
| 2008-03-17 00:00:00 | 2008-09-05 00:00:00 |
| 本地 | |
| 当运行GNOME On-Screen Keyboard (GOK)时,Sun Solaris 10 Java Desktop System (JDS)的xscreensaver中的未明漏洞。本地用户通过可以引致屏幕保护(screen saver) 崩溃的未知向量,以绕过权限认证。 | |
–
公告与补丁
|
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: http://www.sun.com/software/solaris/ |
–
漏洞信息
42873 |
|
| Solaris Java Desktop System (JDS) XscreenSaver Unspecified Authentication Bypass | |
Authentication Management |
|
| Loss of Integrity | Patch / RCS |
| Vendor Verified | |
–
漏洞描述
–
时间线
2008-03-12 |
Unknow |
| Unknow | Unknow |
–
解决方案
| Currently, there are no known workarounds or upgrades to correct this issue. However, Sun has released a patch to address this vulnerability. |
–
相关参考
|
–
漏洞作者
| Unknown or Incomplete |






![[八卦] 王婷婷—揭秘一个大三女生的性爱录像-微慑信息网-VulSee.com](http://free.86hy.com/crack/pic/1.jpg)
![[随笔]今天国际警察节-微慑信息网-VulSee.com](http://photo.sohu.com/20041017/Img222528326.jpg)

青云网
