---------------------------------------------------------------------- Want a new job? http://secunia.com/secunia_security_specialist/ http://secunia.com/hardcore_disassembler_and_reverse_engineer/ ---------------------------------------------------------------------- TITLE: Sun Solaris crontab Privilege Escalation Vulnerability SECUNIA ADVISORY ID: SA30482 VERIFY ADVISORY: http://secunia.com/advisories/30482/ CRITICAL: Less critical IMPACT: Privilege escalation WHERE: Local system OPERATING SYSTEM: Sun Solaris 8 http://secunia.com/product/94/ Sun Solaris 9 http://secunia.com/product/95/ Sun Solaris 10 http://secunia.com/product/4813/ DESCRIPTION: A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to a race condition in the Solaris crontab(1) utility and can be exploited to inject arbitrary cron jobs into another local user's crontab file. SOLUTION: Apply patches. -- SPARC Platform -- Solaris 8: Apply patch 109007-26 or later. Solaris 9: Apply patch 122300-27 or later. Solaris 10: Apply patch 137017-02 or later. OpenSolaris: Fixed in build snv_93 or later. -- x86 Platform -- Solaris 8: Apply patch 109008-26 or later. Solaris 9: Apply patch 122301-27 or later. Solaris 10: Apply patch 137018-02 or later. OpenSolaris: Fixed in build snv_93 or later. PROVIDED AND/OR DISCOVERED BY: The vendor credits Charles Morris, Old Dominion University. ORIGINAL ADVISORY: http://sunsolve.sun.com/search/document.do?assetkey=1-66-237864-1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------