There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot browser bsod computer cpu crash css dell desktop driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware missing monitor network networking outlook outlook 2003 outlook 2007 outlook express password popups problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
DOS/PDA/Other
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > DOS/PDA/Other >
Solaris Vulnerabilities: Sept


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator with 18,328 posts.
 
Join Date: Mar 2001
Location: Bradford, England
08-Oct-2001, 06:55 PM #1
Wink Solaris Vulnerabilities: Sept
Hiya

Sun Solaris Unix domain socket has insecure access permissions

The Unix domain socket implementation in Sun Solaris versions 2.5, 2.5.1, and 2.6 and possibly other BSD or Unix-based operating systems has insecure access permissions, which allow unauthorized access. A local attacker could exploit this vulnerability by connecting to the socket to disrupt or control the application it is connected to.


Platforms Affected:
FreeBSD: All Versions
Solaris 2.5
Solaris 2.5.1
Solaris 2.6

http://xforce.iss.net/static/7172.php

Sun Solaris aspppd /tmp/.asppp.fifo file symlink attack

Sun Solaris versions 2.4, 2.5, and 2.5.1 could allow a local attacker to launch a symlink attack, caused by a vulnerability in the aspppd tool. Aspppd creates the /tmp/.asppp.fifo file in the /tmp directory insecurely. A local attacker could use this vulnerability to create a symbolic link in the /tmp directory to modify arbitrary files and gain root privileges on the system.


Platforms Affected:
Solaris 2.4
Solaris 2.5
Solaris 2.5.1

http://xforce.iss.net/static/7173.php

DFS login could allow unauthorized access to resources if users are in too many groups

Transarc DCE version 1.1 running the Distributed File System (DFS) could allow a local attacker to gain unauthorized access to resources, caused by a vulnerability in the integrated login. If a local attacker were to be placed into too many groups (exceeds NGROUPS_MAX-1), the groups in the DCE registry and in /etc/group would have an incorrect grouplist at login.


Platforms Affected:
Solaris 2.4
Solaris 2.5
Transarc DCE/DFS 1.1

http://xforce.iss.net/static/7154.php

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 06:51 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.