Executive brief
A vulnerability in the calendar manager service of SunOS allows remote attackers to gain full administrative control over the system. By exploiting this flaw, an attacker can overwrite critical system files, potentially leading to a complete system takeover or permanent data loss. This affects older Solaris environments that rely on the rpc.cmsd service for scheduling and calendar functions.
Technical details
The rpc.cmsd (Calendar Manager Service Daemon) in SunOS/Solaris contains a vulnerability that allows for arbitrary file overwriting. The flaw is accessible via the network through Remote Procedure Calls (RPC). An unauthenticated remote attacker can leverage this to overwrite sensitive system files, such as configuration files or binaries, with arbitrary data. This typically leads to a privilege escalation to root. The vulnerability affects Solaris versions 2.3 through 2.5.1.
Affected products
- Sun Microsystems SunOS 5.3, 5.4, 5.5, 5.5.1 (Solaris 2.3, 2.4, 2.5, 2.5.1)
Timeline
- 1998-03-01: disclosed
- 1998-03-01: advisory