Executive brief
A vulnerability in the Solaris operating system's system definition utility allows local users to access sensitive system memory. This could allow an attacker who already has a basic user account to gain full administrative control (root privileges) over the machine. Such an exploit could lead to a total compromise of the system's data and operations.
Technical details
A vulnerability exists in the sysdef command within SunOS and Solaris environments. The utility does not properly restrict access to kernel memory, allowing a local, unprivileged user to read sensitive data directly from the kernel. By leveraging this unauthorized memory access, an attacker can extract credentials or manipulate system state to escalate their privileges to root. The issue affects Solaris versions 2.3 through 2.5.1 and SunOS versions 5.3 through 5.5.1.
Affected products
- Sun Microsystems Solaris 2.3, 2.4, 2.5, 2.5.1
- Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1
Timeline
- 1997-10-01: disclosed: Initial NVD publication date