CVE-2017-3276Oracle Solaris Operating System vulnerability

4 documents4 sources
Severity
5.7MEDIUMNVD
OSV7.8
EPSS
0.0%
top 85.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateMay 13

Description

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Solaris accessible data and unauthorized

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 0.5 | Impact: 5.2

Affected Packages3 packages

NVDoracle/solaris11.3
Ubuntushadow_project/shadow< 1:4.1.5.1-1ubuntu9.5+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xfrc-3x4c-8gwv: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver)2022-05-13
OSV
shadow regression2017-05-17
CVEList
CVE-2017-3276: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver)2017-01-27
CVE-2017-3276 — Oracle vulnerability | cvebase