Note: This is an archival copy of Security Sun Alert 201448 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1001091.1.
Article ID : 1001091.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2003-06-03
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

A Security Vulnerability With The "/usr/lib/utmp_update" Command May Allow Local Unauthorized Privileges



Category
Security

Release Phase
Resolved

Product
Solaris 9 Operating System
Solaris 2.6 Operating System
Solaris 7 Operating System
Solaris 8 Operating System

Bug Id
4659277

Date of Resolved Release
05-JUN-2003

Impact

A local unprivileged user may be able to gain unauthorized root privileges due to a buffer overflow involving the Solaris "/usr/lib/utmp_update" command.


Contributing Factors

This issue can occur in the following releases:

SPARC Platform

  • Solaris 2.6 without patch 113754-02
  • Solaris 7 without patch 113752-02
  • Solaris 8 without patch 113650-02
  • Solaris 9 without patch 113718-02
x86 Platform
  • Solaris 2.6 without patch 113755-02
  • Solaris 7 without patch 113753-02
  • Solaris 8 without patch 113651-02
  • Solaris 9 without patch 113996-02

Symptoms

There are no predictable symptoms that would show the described issue has been exploited to gain unauthorized root access to a system.


Workaround

There is no workaround. Please see the "Resolution" section below.


Resolution

This issue is addressed in the following releases:

SPARC Platform

  • Solaris 2.6 with patch 113754-02 or later
  • Solaris 7 with patch 113752-02 or later
  • Solaris 8 with patch 113650-02 or later
  • Solaris 9 with patch 113718-02 or later
x86 Platform
  • Solaris 2.6 with patch 113755-02 or later
  • Solaris 7 with patch 113753-02 or later
  • Solaris 8 with patch 113651-02 or later
  • Solaris 9 with patch 113996-02 or later


Modification History

References

113754-02




Attachments
This solution has no attachment