vendor:
Solaris
by:
Chris Sheldon
N/A
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Solaris
Affected Version From: Solaris 2.5.1
Affected Version To: Solaris 2.5.1
Patch Exists: YES
Related CWE:
CPE: cpe:2.3:o:sun:solaris:2.5.1
Platforms Tested: Solaris 2.5.1
1997
lpNet & temp file exploit
This exploit allows an attacker to escalate their privileges by exploiting a vulnerability in the lpNet service and the creation of temporary files with improper permissions. By creating a symbolic link to the .rhosts file of the lp user in the temporary file location, the attacker can gain root access or execute arbitrary commands with elevated privileges.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the necessary patches provided by Sun (patch 103959-03) or update to a patched version of the Solaris operating system. Additionally, ensure that the lpNet service is running with the least privileges necessary and that temporary files are created with proper permissions.