CVE-2008-4131 describes multiple unspecified vulnerabilities in Sun Solaris versions 8 through 10, specifically within the vi, ex, vedit, view, and edit text editors. Local users can exploit these flaws to gain elevated privileges by manipulating tags using the -t option or the :tag command. With a CVSS score of 7.2, this vulnerability is considered highly severe, allowing for complete compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. While not actively exploited in the wild and not listed in CISA's KEV catalog, an ExploitDB entry (EDB-32393) exists, indicating public exploit code for command execution, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8CPE matchmatch criteria | cpe:2.3:o:sun:solaris:8:*:sparc:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:o:sun:solaris:8:*:x86:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:sun:solaris:9:*:sparc:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:sun:solaris:9:*:x86:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:sun:solaris:10:*:sparc:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.