|
|
| |
"Solaris PC NetLink software (based on AT&T Advanced Server for Unix) delivers native Windows NT network services--which include directory, authentication, and file-and-print services--on Solaris environment servers."
A vulnerability within PC Netlink allows locally stored files to be opened insecurely and possibly modified. |
| |
Credit:
The original article can be found at:
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102117-1
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102122-1
|
| |
Vulnerable Systems:
* PC NetLink 2.0 (for Solaris 7, 8 and 9) without patch 121209-01
Immune Systems:
* PC NetLink 2.0 (for Solaris 7, 8 and 9) with patch 121209-01 or later
A security vulnerability in the "/opt/lanman/sbin/slsmgr" and "/etc/init.d/slsadmin" command in PC NetLink allows files to be opened insecurely, which could allow an unprivileged local user the ability to write to the filesystem with the permissions of the user running the script. If the script is run as "root," it may allow a local unprivileged user to gain elevated privileges on the system and run arbitrary commands.
|
|
|