Re: [Full-disclosure] Solaris 9/10 ld.so fun

From: Przemyslaw Frasunek (venglin_at_freebsd.lublin.pl)
Date: 06/28/05

  • Next message: Reed Arvin: "Multiple buffer overflows exist in Infradig Systems Inframail Advantage Server Edition 6.0"
    Date: Tue, 28 Jun 2005 18:17:02 +0200
    To: full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com
    
    

    Przemyslaw Frasunek wrote:
    > - SunOS 5.10 Generic i86pc i386 i86pc
    > - SunOS 5.9 Generic_112233-12 sun4u

    This vulnerability was introduced by one of the recent patches for Solaris 9,
    possibly 112963. Ld.so patched with 112963-08 is not vulnerable -- it does
    not allow LD_AUDIT for set[ug]id binaries, but upgrading to 112963-16
    definitly makes ld.so exploitable.

    Up-to-date Solaris 8 boxes are also vulnerable. Solaris 10 boxes are
    vulnerable, both patched and unpatched.

    -- 
    * Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NICHDL: PMF9-RIPE *
    * JID: venglin@jabber.atman.pl ** PGP ID: 2578FCAD ** HAM-RADIO: SQ8JIV *
    

  • Next message: Reed Arvin: "Multiple buffer overflows exist in Infradig Systems Inframail Advantage Server Edition 6.0"

    Relevant Pages

    • Re: [Full-disclosure] Solaris 9/10 ld.so fun
      ... > This vulnerability was introduced by one of the recent patches for Solaris 9, ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Solaris 9/10 ld.so fun
      ... > This vulnerability was introduced by one of the recent patches for Solaris 9, ... heart he dreams himself your master. ...
      (Bugtraq)
    • Re: matlab 7 crash on solaris 9
      ... Manuel Oetiker wrote: ... > matlab is crashing after we applied the newest patches on our ... > boxes. ... I am seeing the same problem on Solaris 10. ...
      (comp.soft-sys.matlab)
    • Re: Automatic Security Patching for Debian
      ... I personally would not want anything to scan my boxes for a ... vulnerability than open up my box enough that the same thing that ... Kristian Du wrote: ... > the net existing patches and installs them for you automatically? ...
      (Security-Basics)
    • Re: [Full-disclosure] Solaris 9/10 ld.so fun
      ... This vulnerability was introduced by one of the recent patches for Solaris 9, ... Up-to-date Solaris 8 boxes are also vulnerable. ...
      (Full-Disclosure)