Secunia Security Advisory - A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges.
8d7b57d7bd8648d47d0e67edf7d3ddcd9d02c53d4d457eb11da9555674d87cc5
----------------------------------------------------------------------
Do you need accurate and reliable IDS / IPS / AV detection rules?
Get in-depth vulnerability details:
http://secunia.com/binary_analysis/sample_analysis/
----------------------------------------------------------------------
TITLE:
Sun Solaris Editors Tag File Handling Privilege Escalation
Vulnerability
SECUNIA ADVISORY ID:
SA31895
VERIFY ADVISORY:
http://secunia.com/advisories/31895/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
OPERATING SYSTEM:
Sun Solaris 10
http://secunia.com/advisories/product/4813/
Sun Solaris 9
http://secunia.com/advisories/product/95/
Sun Solaris 8
http://secunia.com/advisories/product/94/
DESCRIPTION:
A vulnerability has been reported in Sun Solaris, which can be
exploited by malicious, local users to gain escalated privileges.
The vulnerability is caused due to an unspecified error within the
handling of tag files in the Solaris editors (vi, ex, vedit, view,
and edit). This can be exploited to execute arbitrary code with
privileges of another user when the "-t" option or the ":tag" command
in a Solaris text editor is used.
The vulnerability is reported in Solaris 8,9, and 10 for the SPARC
and x86 platforms.
SOLUTION:
Apply patches.
-- SPARC Platform --
Solaris 8:
Apply patch 110903-08 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-110903-08-1
Solaris 9:
Apply patch 113031-04 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-113031-04-1
Solaris 10:
Apply patch 120830-06 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120830-06-1
-- x86 Platform --
Solaris 8:
Apply patch 110904-08 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-110904-08-1
Solaris 9:
Apply patch 116479-02 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-116479-02-1
Solaris 10:
Apply patch 120831-06 or later.
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120831-06-1
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Eli the Bearded.
ORIGINAL ADVISORY:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-237987-1
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------