CVE-2007-2617
UnknownEPSS 3.80%
Last modified
CVE-2007-2617 is a vulnerability of currently unknown severity. srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.. EPSS estimates a 3.80% chance of exploitation in the next 30 days.
Description
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Net Connect Software | 3.2.3 |
| Sun | Net Connect Software | 3.2.4 |
References
- http://secunia.com/advisories/25194Vendor Advisory
- http://secunia.com/advisories/25194Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2617?
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.
How severe is CVE-2007-2617?
Severity scoring for CVE-2007-2617 is pending analysis. The EPSS model estimates a 3.80% probability of exploitation in the next 30 days.
How do I fix CVE-2007-2617?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2611Multiple PHP remote file inclusion vulnerabilities in CGX 20…
- CVE-2007-2612SQL injection vulnerability in libs/Wakka.class.php in Wikka…
- CVE-2007-2613WikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a …
- CVE-2007-2614PHP remote file inclusion vulnerability in examples/widget8.…
- CVE-2007-2615Multiple PHP remote file inclusion vulnerabilities in Crie s…
- CVE-2007-2616Stack-based buffer overflow in the SSL version of the NMDMC.…
- CVE-2007-2618CRLF injection vulnerability in index.php in Drake CMS 0.4.0…
- CVE-2007-2619Symantec pcAnywhere 11.5.x and 12.0.x retains unencrypted lo…
- CVE-2007-2620PHP remote file inclusion vulnerability in inc/config.inc.ph…
- CVE-2007-2621SQL injection vulnerability in event_view.php in Thyme Calen…
- CVE-2007-2622Multiple SQL injection vulnerabilities in TaskDriver 1.2 and…
- CVE-2007-2623Multiple buffer overflows in RControl.dll in Remote Display …
Are you affected by CVE-2007-2617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
