Executive brief
The Kodak Color Management System (KCMS) included with Sun Solaris operating systems contains a security flaw that allows a local user to gain full administrative control. By exploiting this vulnerability, an individual with basic access to the system can overwrite critical system files. This can lead to a total compromise of the server, allowing the attacker to access sensitive data or disrupt operations.
Technical details
A vulnerability exists in the Kodak Color Management System (KCMS) library/service as distributed with Sun Solaris 2.5 and 2.5.1. The flaw allows a local attacker to perform arbitrary file writes with elevated privileges. By targeting sensitive system files (such as /etc/passwd or system binaries), an unprivileged local user can escalate their privileges to root. The vulnerability is categorized as an arbitrary file write leading to privilege escalation. Patch information is not explicitly detailed in the provided NVD record, but the issue is historically associated with early Solaris 2.x releases.
Affected products
- Sun Microsystems Solaris 2.5, 2.5.1
- Sun Microsystems SunOS 5.5, 5.5.1
Timeline
- 1996-07-31: disclosed: Initial publication date in NVD