CVE-2017-3276
published 2017-01-27CVE-2017-3276: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that…
PriorityP422medium5.7CVSS 3.0
AVLACHPRHUINSUCNIHAH
EPSS
0.33%
25.1th percentile
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS v3.0 Base Score 5.7 (Integrity and Availability impacts).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | solaris | — | — |
| oracle | solaris_operating_system | — | — |
| shadow_project | shadow | >= 0 < 1:4.1.5.1-1ubuntu9.5 | 1:4.1.5.1-1ubuntu9.5 |
| shadow_project | shadow | >= 0 < 1:4.2-3.1ubuntu5.3 | 1:4.2-3.1ubuntu5.3 |
CVSS provenance
nvdv3.05.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.0LOWAV:L/AC:M/Au:S/C:N/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xfrc-3x4c-8gwv: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver)
ghsa_unreviewed·2022-05-13
CVE-2017-3276 [MEDIUM] GHSA-xfrc-3x4c-8gwv: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS v3.0 Base Score 5.7 (Integrity and Availability impacts).
OSV
shadow regression
osv·2017-05-17·CVSS 7.8
CVE-2016-6252 shadow regression
shadow regression
USN-3276-1 intended to fix a vulnerability in su. The solution introduced
a regression in su signal handling. This update modifies the security fix.
We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95544http://www.securitytracker.com/id/1037641http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95544http://www.securitytracker.com/id/1037641
2017-01-27
Published