Executive brief
A vulnerability in the installation scripts for Sun Source (sunsrc) software allows local users to gain full administrative control over the system. By exploiting specific installation programs, a standard user can elevate their privileges to root, potentially leading to complete system compromise and unauthorized access to all data.
Technical details
A privilege escalation vulnerability exists in the Sun Source (sunsrc) tape installation process. The issue stems from the 'makeinstall' and 'winstall' programs being installed with setuid root permissions. A local, unprivileged attacker can execute these programs to bypass security controls and gain root-level access. This vulnerability is reachable only by users with local access to the system where the sunsrc tapes are being installed or have been installed. Patches were historically provided by Sun Microsystems via security bulletin 107.
Affected products
- Sun Microsystems Sun Source (sunsrc) Tapes
Timeline
- 1991-05-20: advisory: Initial NVD publication date
- 1991-05-20: disclosed: Date of CERT advisory CA-1991-07 and Sun security bulletin 107