Executive brief
A vulnerability in the SunView selection service allows unauthorized individuals to remotely access and read files on affected systems. This component is part of an older graphical user interface environment for Sun workstations. An exploit could lead to the exposure of sensitive system or user data, potentially compromising the confidentiality of the entire workstation.
Technical details
The selection_svc facility in Sun Microsystems' SunView (SunTools) environment contains a vulnerability that allows remote file disclosure. By interacting with the selection service over the network, an unauthenticated attacker can bypass intended access controls to read arbitrary files from the host system. This is a legacy vulnerability affecting early SunOS environments. The root cause is a lack of proper validation or access control within the RPC-based selection service, which was designed to facilitate data exchange between applications but can be abused to retrieve file contents.
Affected products
- Sun Microsystems SunView (SunTools)
Timeline
- 1990-08-14: disclosed