Sun Solaris newgrp(1) Buffer Overflow Lets Remote Users Gain Root Privileges
|
|
SecurityTracker Alert ID: 1013462
|
|
SecurityTracker URL: http://securitytracker.com/id?1013462
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Mar 17 2005
|
Impact: Execution of arbitrary code via local system, User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Sun Alert
|
Version(s): 7, 8, and 9
|
Description: A vulnerability was reported in Sun Solaris in the newgrp command. A local user can obtain root privileges.
A local user can trigger a buffer overflow in the newgrp(1) command to execute arbitrary code with root privileges.
Solaris 7, 8, and 9 are affected. Solaris 10 is not affected.
|
Impact: A local user can execute arbitrary code with root privileges.
|
Solution: Sun has issued the following fixes:
SPARC Platform
* Solaris 7 with patch 118737-01 or later
* Solaris 8 with patch
116993-01 or later
* Solaris 9 with patch 117445-01 or later
x86 Platform
* Solaris 7 with patch 118738-01 or later
* Solaris 8 with patch 116994-01 or later
* Solaris 9 with patch 117446-01 or later
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-57710-1 (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 17 Mar 2005 08:43:56 -0500
Subject: http://sunsolve.sun.com/search/document.do?assetkey=1-26-57710-1
|
> Security Vulnerability in the newgpr(1) Command May Allow Unauthorized Root
> Privileges
Sun reported a buff overflow in the newgrp(1) command. A local user may be able to
gain root privileges.
Solaris 7, 8, and 9 are affected. Solaris 10 is not affected.
Sun has issued the following fixes:
SPARC Platform
* Solaris 7 with patch 118737-01 or later
* Solaris 8 with patch 116993-01 or later
* Solaris 9 with patch 117445-01 or later
x86 Platform
* Solaris 7 with patch 118738-01 or later
* Solaris 8 with patch 116994-01 or later
* Solaris 9 with patch 117446-01 or later
-----
* Sun Alert ID: 57710
* Synopsis: Security Vulnerability in the newgrp(1) Command May Allow Unauthorized Root Privilege s
* Category: Security
* Product: Solaris
* BugIDs: 4705393
* Avoidance: Workaround, Patch
* State: Resolved
* Date Released: 16-Mar-2005
* Date Closed: 16-Mar-2005
* Date Modified:
|
|