Executive brief
A vulnerability in the remote login service of SunOS allows a user who already has access to a system to gain full administrative (root) control. This could allow an unauthorized individual to access sensitive data, modify system files, or disrupt operations on the affected machine. This issue impacts older versions of the SunOS operating system.
Technical details
A privilege escalation vulnerability exists in the in.rlogind daemon of SunOS versions 4.0.3 and 4.0.3c. The flaw allows a local attacker with standard user access to exploit the remote login daemon to execute commands with root-level permissions. The vulnerability is triggered locally, requiring the attacker to have an existing shell or account on the target system. Successful exploitation results in a complete compromise of the host's confidentiality, integrity, and availability. Patches were historically made available via Sun Microsystems and documented in CERT advisory CA-1991-02.
Affected products
- Sun Microsystems SunOS 4.0.3, 4.0.3c
Timeline
- 1991-03-27: advisory: NVD published date
- 1991-03-27: disclosed: Initial disclosure via CERT CA-1991-02