Sun Solaris passwd(1) May Let Local Users Obtain Root Privileges
|
|
SecurityTracker Alert ID: 1009240
|
|
CVE Reference: CAN-2004-0360
(Links to External Site)
|
Updated: Mar 19 2004
|
Original Entry Date: Feb 27 2004
|
Impact: Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Solaris 8, 9
|
Description: A vulnerability was reported in the Sun Solaris passwd(1) command. A local user may be able to obtain root privileges.
Sun did not provide details regarding the nature of the flaw.
The vulnerability affects Solaris 8 and 9. Solaris 7 is not affected
by this issue.
Sun credits Tim Wort with reporting this flaw.
[Editor's note: Rafal Bielecki reported a vulnerability affecting
Solaris 9 where a local user can trigger a segmentation fault by changing the password to a string that is longer than 80 characters.
It is not clear whether this fix from Sun is related to that report or not. We will update this Alert when we receive clarification.]
|
Impact: A local user may be able to gain elevated privileges.
|
Solution: Sun has issued the following fixes:
SPARC Platform
Solaris 8 with patch 108993-32 or later
Solaris 9 with patch 113476-11 or later
x86 Platform
Solaris 8 with patch 108994-32 or later
Solaris 9 with patch 114242-07 or later
|
Vendor URL: sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57454 (Links to External Site)
|
Cause: Not specified
|
Underlying OS: UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 27 Feb 2004 07:37:43 -0500
Subject: http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57454
|
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57454
57454 Security Vulnerability Involving the passwd(1) Command 26 Feb 2004
Sun reports that a local user may be able to gain root privileges due to a security issue
with the passwd(1) command.
Sun credits Tim Wort with reporting this flaw.
The vulnerability affects Solaris 8 and 9. Solaris 7 is not affected by this issue.
Sun has issued the following fixes:
SPARC Platform
Solaris 8 with patch 108993-32 or later
Solaris 9 with patch 113476-11 or later
x86 Platform
Solaris 8 with patch 108994-32 or later
Solaris 9 with patch 114242-07 or later
-----
Sun Alert ID: 57454
Synopsis: Security Vulnerability Involving the passwd(1) Command
Category: Security
Product: Solaris
BugIDs: 4793719
Avoidance: Patch
State: Resolved
Date Released: 26-Feb-2004
Date Closed: 26-Feb-2004
Date Modified:
|
|