Executive brief
A vulnerability in the Solaris volume management utility allows a local user to read any file on the system, including sensitive configuration and password files. This could lead to a total compromise of the operating system and unauthorized access to private data. The issue affects the volrmmount program, which is used for managing removable media.
Technical details
The volrmmount utility in Sun Solaris (specifically version 2.6 and potentially others) contains a vulnerability that allows local users to read arbitrary files. The flaw exists in the handling of file permissions or paths within the volume management service, enabling an unprivileged user to bypass standard access controls. By exploiting this, an attacker with local shell access can view sensitive system files such as /etc/shadow. This is a local privilege escalation vector that can lead to full system compromise. Sun Microsystems released security bulletin 162 to address this issue.
Affected products
- Sun Microsystems Solaris 2.6 and earlier
Timeline
- 1998-02-01: disclosed
- 1998-02-01: advisory: NVD publication date