vendor:
Solaris License Manager
by:
Iconoclast
7.2
CVSS
HIGH
Symlink Attack
59
CWE
Product Name: Solaris License Manager
Affected Version From: 2.5.2001
Affected Version To: 2.6
Patch Exists: NO
Related CWE: N/A
CPE: Solaris
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Solaris
1998
Solaris License Manager Symlink Attack
The Solaris License Manager that ships with versions 2.5.1 and 2.6 is vulnerable to multiple symlink attacks. License Manager creates lockfiles owned by root and set mode 666 which it writes to regularily. It follows symlinks. An attacker can create a symlink to a target user's .rhosts file, and then wait for the License Manager to write to it, thus allowing the attacker to gain root access locally.
Mitigation:
Ensure that the License Manager is running with the least privileges necessary and that the lockfiles are not writable by any other user.