Executive brief
A vulnerability in the 'su' utility of older SunOS operating systems allows local users to gain full administrative control of the system. By placing a malicious program in a common directory, an attacker can trick the system into executing their code when an administrator attempts to switch user accounts. This can lead to a complete compromise of the server and all data stored on it.
Technical details
The /usr/5bin/su executable in SunOS 4.1.3 and earlier (and corresponding Solaris 1.x versions) contains an insecure default search path configuration that includes the current working directory ('.'). A local attacker can exploit this by placing a malicious executable with the same name as a common system command in a directory and waiting for a privileged user to execute 'su' from that location. Because the current directory is searched, the malicious 'Trojan horse' program is executed with the privileges of the user running the su command, typically leading to root compromise. This is a classic path-based privilege escalation vulnerability. Patches were historically released by Sun Microsystems to address this behavior.
Affected products
- Sun Microsystems SunOS 4.1.3 and earlier
- Sun Microsystems Solaris 1.1 and earlier
Timeline
- 1993-09-17: disclosed: Initial publication date