Executive brief
A security flaw in the Solaris 2.6 operating system (specifically the HW3/98 release) incorrectly sets the permissions of a system administration tool to be world-writable. This allows any user with local access to the system to replace the legitimate tool with a malicious program. An attacker could use this to gain full administrative control over the server, potentially leading to data theft or complete system compromise.
Technical details
The vulnerability is a result of improper file permissions (mode 0777) assigned to /usr/bin/admintool during the installation of Solaris 2.6 HW3/98. Under normal conditions, this binary should be setuid root with restricted write access (e.g., mode 04555). Because the file is world-writable, any local user can overwrite the binary with a Trojan horse. When an administrative user subsequently executes the compromised admintool, the attacker's code runs with the privileges of that user, typically leading to a full root compromise. The fix involves manually correcting the file permissions to 04555 or removing the binary if it is not required.
Affected products
- Sun Microsystems Solaris 2.6 HW3/98
Timeline
- 1998-05-07: disclosed: Public disclosure on Bugtraq mailing list
- 1998-05-07: advisory: NVD publication date