vendor:
Solaris 11.x
by:
Marco Ivaldi
8.8
CVSS
HIGH
Design Error Vulnerability
20
CWE
Product Name: Solaris 11.x
Affected Version From: 5.06
Affected Version To: 5.39
Patch Exists: YES
Related CWE: CVE-2019-3010
CPE: o:oracle:solaris:11
Other Scripts:
N/A
Platforms Tested: Oracle Solaris 11.x (tested on 11.4 and 11.3)
2019
Local privilege escalation on Solaris 11.x via xscreensaver
A local attacker can gain root privileges by exploiting a design error vulnerability in the xscreensaver distributed with Solaris. The attacker can create (or append to) arbitrary files on the system, by abusing the -log command line switch introduced in version 5.06. This flaw can be leveraged to cause a denial of service condition or to escalate privileges to root.
Mitigation:
Oracle Solaris 11.x users should upgrade to the latest version of xscreensaver.