Executive brief
A vulnerability in older versions of the Solaris operating system allows local users to gain elevated privileges. By forcing certain system programs to crash, a user can trick the system into creating or overwriting sensitive files that they would normally not have permission to access. This could allow an attacker to modify system configuration files or gain administrative control over the machine.
Technical details
A vulnerability exists in the core dump handling of Solaris 2.4 (SunOS 5.4). While the system is intended to prevent core dumps for processes where the effective user ID differs from the real user ID, it fails to properly restrict set-gid programs when the real user is not in the set-gid group. A local attacker can exploit this by creating a symbolic link named 'core' in a writable directory (or leveraging group-writable system directories like /usr/sbin) pointing to a sensitive file (e.g., /etc/passwd). By executing a set-gid utility like 'dmesg' and forcing it to terminate with a signal that triggers a core dump, the attacker can overwrite the target file with the memory image of the process. This can lead to arbitrary file creation or modification with the privileges of the program's group. The issue is resolved by applying kernel jumbo patch -35 or later.
Affected products
- Sun Microsystems Solaris 2.4 (SunOS 5.4) before kernel jumbo patch -35
Timeline
- 1996-08-03: disclosed: Initial disclosure on Bugtraq mailing list
- 1996-08-03: advisory: NVD publication date