Oracle Solaris - 'rdist' Privilege Escalation

EDB-ID:

34309


Type:

dos


Platform:

Solaris

Date:

2010-07-13


source: https://www.securityfocus.com/bid/41612/info

Oracle Solaris is prone to a local privilege-escalation vulnerability.

Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.

The following products are affected:

Solaris 10
OpenSolaris 

/usr/bin/rdist -cDwh file_that_is_hardlink rlogin_host:LONG_STRING