vendor:
Solaris
by:
Marco Ivaldi
7.2
CVSS
HIGH
Privilege Escalation
N/A
CWE
Product Name: Solaris
Affected Version From: Solaris 11.x
Affected Version To: Solaris 11.x
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Solaris 11.x X86
2019
Solaris xscreensaver 11.4 – Privilege Escalation
Exploitation of a design error vulnerability in xscreensaver, as distributed with Solaris 11.x, allows local attackers to create (or append to) arbitrary files on the system, by abusing the -log command line switch introduced in version 5.06. This flaw can be leveraged to cause a denial of service condition or to escalate privileges to root. This is a Solaris-specific vulnerability, caused by the fact that Oracle maintains a slightly different codebase from the upstream one (CVE-2019-3010).
Mitigation:
No known mitigation or remediation for this vulnerability