CVE-2009-3706 describes an unspecified vulnerability within the ZFS filesystem affecting Sun Solaris 10 and OpenSolaris versions snv_100 through snv_117. This flaw permits local users to circumvent intended restrictions of the file_chown_self privilege by manipulating the chown system call. With a CVSS score of 4.4, this vulnerability is of medium complexity to exploit locally, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, and it has garnered no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
snv_100CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_100:*:sparc:*:*:*:*:* | ||
snv_101CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_101:*:sparc:*:*:*:*:* | ||
snv_102CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_102:*:sparc:*:*:*:*:* | ||
snv_103CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_103:*:sparc:*:*:*:*:* | ||
snv_104CPE matchmatch criteria | cpe:2.3:o:sun:opensolaris:snv_104:*:sparc:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.