Executive brief
A vulnerability in older versions of the SunOS operating system allows a local user to gain full administrative (root) control over the system. This is caused by improper security settings on certain system files and directories, such as those used for system crash data. An attacker with basic access to the machine could exploit this to access sensitive data or disrupt operations.
Technical details
A privilege escalation vulnerability exists in SunOS versions 4.1, 4.1.1, 4.1.2, and 4.1.3 due to insecure file system permissions. Specifically, certain sensitive directories and files, including the 'crash' directory, were configured with permissions that allowed non-privileged local users to modify or interact with them in ways that lead to root access. An attacker with local shell access can exploit these weak permissions to elevate their privileges to the superuser level. The vulnerability was originally addressed in CERT advisory CA-1993-03.
Affected products
- Sun Microsystems SunOS 4.1 through 4.1.3
Timeline
- 1993-02-03: advisory: NVD published date and original CERT advisory release