Solaris 8 dtscreen Authentication Bypass Vulnerability
BID:5040
Info
Solaris 8 dtscreen Authentication Bypass Vulnerability
| Bugtraq ID: | 5040 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 17 2002 12:00AM |
| Updated: | Jun 17 2002 12:00AM |
| Credit: | Reported by Jon Masters <[email protected]>. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc |
| Not Vulnerable: | |
Discussion
Solaris 8 dtscreen Authentication Bypass Vulnerability
Solaris 8 ships with CDE utilities, including dtscreen which provides screen saver functionality, and dtsession which may lock the terminal when invoking dtscreen.
Reportedly, a physically local user may cause the screen saver process to crash and dump core. If this is accomplished, the current session will be available, granting local access as the authenticated user. This may be accomplished by rapidly pressing the 'Shift' and 'Return' keys.
Solaris 8 ships with CDE utilities, including dtscreen which provides screen saver functionality, and dtsession which may lock the terminal when invoking dtscreen.
Reportedly, a physically local user may cause the screen saver process to crash and dump core. If this is accomplished, the current session will be available, granting local access as the authenticated user. This may be accomplished by rapidly pressing the 'Shift' and 'Return' keys.
Exploit / POC
Solaris 8 dtscreen Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Solaris 8 dtscreen Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.