Sun Solaris pkgadd Inappropriate File Permissions Vulnerability
BID:5208
Info
Sun Solaris pkgadd Inappropriate File Permissions Vulnerability
| Bugtraq ID: | 5208 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 10 2002 12:00AM |
| Updated: | Jul 10 2002 12:00AM |
| Credit: | Published in Sun(sm) Alert Notification. |
| Vulnerable: |
Sun Solaris 2.5.1 Sun Solaris 8_sparc Sun Solaris 7.0 Sun Solaris 2.6 |
| Not Vulnerable: |
Sun Solaris 9 |
Discussion
Sun Solaris pkgadd Inappropriate File Permissions Vulnerability
Some versions of Sun Solaris support the pkgadd command, which is used to transfer the contents of software packages from the distribution medium and install the software. For a given package, the included files are described in a pkgmap ASCII file.
A file permissions issue exists in versions of Sun Solaris. Under some conditions, it is possible that pkgadd will erroneously install some files with the suid/sguid bit set. These files may additionally be owned by the user or group 'root'. This problem is related to the usage of the '?' character in the relevant pkgmap entry.
Some versions of Sun Solaris support the pkgadd command, which is used to transfer the contents of software packages from the distribution medium and install the software. For a given package, the included files are described in a pkgmap ASCII file.
A file permissions issue exists in versions of Sun Solaris. Under some conditions, it is possible that pkgadd will erroneously install some files with the suid/sguid bit set. These files may additionally be owned by the user or group 'root'. This problem is related to the usage of the '?' character in the relevant pkgmap entry.
Exploit / POC
Sun Solaris pkgadd Inappropriate File Permissions Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.