Executive brief
A vulnerability in the Solaris Solstice AdminSuite, a tool used for managing network information services, allows local users to overwrite critical system files. By exploiting how the software handles file updates, an attacker with access to the system could potentially corrupt data or gain elevated privileges, leading to a full system compromise. This poses a significant risk to the integrity and availability of the affected server.
Technical details
A symbolic link (symlink) race condition exists in Sun Solaris Solstice AdminSuite 2.1. When the application updates the Network Information Service (NIS) database, it fails to properly validate file paths, allowing it to follow symbolic links created by a local attacker. By pointing a symlink to a sensitive system file, a local unprivileged user can cause the administrative tool to overwrite that file with NIS data. This can lead to a denial of service or local privilege escalation if critical configuration files (like /etc/passwd) are targeted. The vulnerability is exploited locally and requires the attacker to time the creation of the symlink during the database update process.
Affected products
- Sun Microsystems Solstice AdminSuite 2.1
Timeline
- 1997-11-10: disclosed
- 1997-11-10: advisory