---------------------------------------------------------------------- Do you need accurate and reliable IDS / IPS / AV detection rules? Get in-depth vulnerability details: http://secunia.com/binary_analysis/sample_analysis/ ---------------------------------------------------------------------- TITLE: Sun Solaris Editors Tag File Handling Privilege Escalation Vulnerability SECUNIA ADVISORY ID: SA31895 VERIFY ADVISORY: http://secunia.com/advisories/31895/ CRITICAL: Less critical IMPACT: Privilege escalation WHERE: Local system OPERATING SYSTEM: Sun Solaris 10 http://secunia.com/advisories/product/4813/ Sun Solaris 9 http://secunia.com/advisories/product/95/ Sun Solaris 8 http://secunia.com/advisories/product/94/ DESCRIPTION: A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to an unspecified error within the handling of tag files in the Solaris editors (vi, ex, vedit, view, and edit). This can be exploited to execute arbitrary code with privileges of another user when the "-t" option or the ":tag" command in a Solaris text editor is used. The vulnerability is reported in Solaris 8,9, and 10 for the SPARC and x86 platforms. SOLUTION: Apply patches. -- SPARC Platform -- Solaris 8: Apply patch 110903-08 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-110903-08-1 Solaris 9: Apply patch 113031-04 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-113031-04-1 Solaris 10: Apply patch 120830-06 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120830-06-1 -- x86 Platform -- Solaris 8: Apply patch 110904-08 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-110904-08-1 Solaris 9: Apply patch 116479-02 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-116479-02-1 Solaris 10: Apply patch 120831-06 or later. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120831-06-1 PROVIDED AND/OR DISCOVERED BY: The vendor credits Eli the Bearded. ORIGINAL ADVISORY: http://sunsolve.sun.com/search/document.do?assetkey=1-66-237987-1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------