>> Sun Solaris PC Netlink "slsadmin" and "slsmgr" Local Vulnerabilities
Title : Sun Solaris PC Netlink "slsadmin" and "slsmgr" Local Vulnerabilities VUPEN ID : VUPEN/ADV-2005-3083 CVE ID : CVE-2005-4552 CWE ID : CWE-OVAL1409
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-12-24
Technical Description
Two vulnerabilities were identified in PC Netlink for Solaris, which could be exploited by local attackers to obtain elevated privileges. These flaws are due to errors in the "/etc/init.d/slsadmin" script and the "/opt/lanman/sbin/slsmgr" command that allow files to be opened insecurely, which could be exploited by an unprivileged local user to write to the filesystem with the permissions of the user running "slsadmin" or "slsmgr", and execute arbitrary commands with "root" privileges (when "slsadmin" or "slsmgr" are run as "root").