Sun Solaris pfexec May Execute Profile Commands With Elevated Privileges
|
|
SecurityTracker Alert ID: 1008893
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jan 30 2004
|
Impact: Root access via local system, User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Solaris 8, 9
|
Description: A vulnerability was reported in the pfexec(1) command in Solaris 8 and 9. A local user may be able to execute a profile command with elevated privileges in certain cases.
Sun reported that a local user with a custom rights profile may be able to execute a profile command with greater privileges than
originally assigned. This can reportedly occur if the execution profiles database (exec_attr(4)) contains an invalid entry for
that custom rights profile.
Solaris 8 and 9 are affected. Solaris 7 is not affected.
Sun notes that root privileges are required
to modify the exec_attr(4) file.
|
Impact: A local user may be able to gain elevated privileges in certain cases.
|
Solution: Sun has issued the following fixes:
SPARC Platform
* Solaris 8 with patch 109007-15 or later
* Solaris 9 with patch
116237-01 or later
x86 Platform
* Solaris 8 with patch 109008-15 or later
* Solaris 9 with patch 116238-01 or later
|
Vendor URL: sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57453 (Links to External Site)
|
Cause: Access control error, Exception handling error
|
Underlying OS: UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 30 Jan 2004 07:35:25 -0500
Subject: http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57453
|
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57453
57453 The pfexec(1) Command May Execute a "Profile" Command With Additional
Privileges 29 Jan 2004
Sun reported that a local user with a custom rights profile may be able to execute a
profile command with greater privileges than originally assigned. This can reportedly
occur if the execution profiles database (exec_attr(4)) contains an invalid entry for that
custom rights profile.
Solaris 8 and 9 are affected. Solaris 7 is not affected.
Sun notes that root privileges are required to modify the exec_attr(4) file.
Sun has issued the following fixes:
SPARC Platform
* Solaris 8 with patch 109007-15 or later
* Solaris 9 with patch 116237-01 or later
x86 Platform
* Solaris 8 with patch 109008-15 or later
* Solaris 9 with patch 116238-01 or later
-----
* Sun Alert ID: 57453
* Synopsis: The pfexec(1) Command May Execute a "Profile" Command With Additional
Privileges
* Category: Security
* Product: Solaris
* BugIDs: 4925561
* Avoidance: Patch
* State: Resolved
* Date Released: 29-Jan-2004
* Date Closed: 29-Jan-2004
* Date Modified:
|
|