Executive brief
A vulnerability in the Expreserve utility, used by the vi and ex text editors, could allow a local user to overwrite sensitive system files. By exploiting how the system handles temporary file preservation during a crash or manual save, an attacker could gain full administrative (root) control over the affected machine. This poses a significant risk to the integrity and security of the operating system.
Technical details
The Expreserve utility, a component of the vi and ex text editors used to recover files after a system crash or unexpected termination, contains a vulnerability that allows for arbitrary file overwriting. A local attacker can exploit this flaw to manipulate file preservation logic, leading to the overwriting of critical system files. Because Expreserve often runs with elevated privileges to manage recovery directories, this can be leveraged to achieve a privilege escalation to root. The vulnerability was notably present in several versions of SunOS and Solaris in the mid-1990s. Patching or updating the affected editor utilities is required to resolve the issue.
Affected products
- Sun Solaris 2.0, 2.1, 2.2, 2.3, 2.4
- Sun SunOS 5.0, 5.1, 5.2, 5.3, 5.4
- Generic vi
- Generic ex
Timeline
- 1996-08-15: advisory: NVD published date
- 1996-12-31: disclosed: CERT advisory published