Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1394
CVE-2004-1394
Description
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
Affected products
3cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*+ 1 more
- cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*
- (no CPE)range: 8, 9
- cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/10755/nvdPatch
- sunsolve.sun.com/search/document.donvdPatchVendor Advisory
- www.auscert.org.au/render.htmlnvdVendor Advisory
- www.osvdb.org/3764nvd
- www.securityfocus.com/bid/9534nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/14988nvd
News mentions
0No linked articles in our index yet.