vendor:
Solaris Recommended Patch Cluster 6/19
by:
Larry W. Cashdollar
7,2
CVSS
HIGH
Local root
264
CWE
Product Name: Solaris Recommended Patch Cluster 6/19
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: x86
2013
Solaris Recommended Patch Cluster 6/19 local root on x86
If the system administrator is updating the system using update manager or smpatch (multi user mode) a local user could execute commands as root. This only affects x86 systems as this code resides under a case statement checking that the platform is intel based. Local root can be achieved by writing to /tmp/diskette_rc.d/rcs9.sh before execution and executing commands as root. Injecting entries into driver_aliases and researching config file can also be used to load own library/driver.
Mitigation:
System administrators should ensure that the system is updated using secure methods and that the system is not vulnerable to local root exploits.