Sun Solaris sadmind vulnerability
- 17 September, 2003 11:58
- Comments
Sun reports that a unprivileged user may be able to execute arbitrary commands with the permissions of the sadmind(1M) daemon on Solaris systems which have sadmind(1M) enabled in inetd.conf(4).
"The sadmind(1M) daemon normally runs with "root" (uid 0) privileges. If the sadmind(1M) daemon is utilizing the default security level authentication mechanism of AUTH_SYS (see secure_rpc(3NSL)), users may be able to forge AUTH_SYS credentials."
The operating systems affected are: Sun Solaris 9, Sun Solaris 8 and Sun Solaris 7.
More information is found at
http://au.sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F56740&zone_32=category%3Asecurity
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Aberdeen Group Analyst Insight Report: Does Your Enterprise Have a “Dropbox Problem?”
- Best Practices for Implementing a Data Warehouse on the Oracle Exadata Database Machine
- 10 Ways to Stretch your storage budgets in virtualised, consolidated environments
- Oracle Database 11g Product Family
- Workshifting: a global market research report
-
Analysis: Microsoft - Too old and too big to survive?
-
A comparison of Telstra's 4G phones
-
Drupal gains ground down under
-
NBN build gaining momentum daily: Quigley
-
Chambers: Networking's changing competitive landscape
-
MYOB Software for Dummies 6E Australian Edition
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Windows 7 for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®









Comments
Post new comment