GS Mag n°12
Next Issues
Subscriptions
Publicity

Google

 Flux RSS
 












Nous gérons le fil d'information de l'officiel du bateau : bateau occasion
 

Vigil@nce: Solaris, file altering via Lightweight Availability Collection Tool
July 2009  by Vigil@nce

A local attacker can use a symbolic link in order to force Lightweight Availability Collection Tool to corrupt a file.

Severity: 1/4

Consequences: data creation/edition

Provenance: user shell

Means of attack: no proof of concept, no attack

Ability of attacker: expert (4/4)

Confidence: confirmed by the editor (5/5)

Diffusion of the vulnerable configuration: high (3/3)

Creation date: 03/07/2009

IMPACTED PRODUCTS

- Sun Solaris
- Sun Trusted Solaris

DESCRIPTION OF THE VULNERABILITY

The Sun Lightweight Availability Collection Tool product collects information on the system availability (boot, panic and halt).

A local attacker can use a symbolic link in order to force Lightweight Availability Collection Tool to corrupt a file.

Technical details are unknown.

CHARACTERISTICS

Identifiers: 261408, 6839596, VIGILANCE-VUL-8838

http://vigilance.fr/vulnerability/Solaris-file-altering-via-Lightweight-Availability-Collection-Tool-8838



< previous      next >















 
Stay informed with Global Security Mag newsletters
copyright® 2007 S.I.M. Publicité