[VulnDiscuss] Re: Immunity Advisory: Solaris kernel loading fun

Jonathan Leffler <[email protected]> Thu, 25 Mar 2004 11:45:05 -0800
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <OF5536D6B9.4BADF737-ON87256E62.006C03F1-88256E62.006BF8DD@us.ibm.com>
Dave Aitel <[email protected]> wrote on 03/23/2004 01:57:43 PM:
> Immunity Research has released an Advisory from the Vulnerability
> Sharing Club into the public domain. This advisory can be found at
> http://www.immunitysec.com/downloads/solaris_kernel_vfs.sxw.pdf
> 
> Technical Summary: There is a vulnerability in Solaris that allows
> local users to load kernel modules without being root. This is handy
> for getting around things like Argus Pitbull (if it still existed) or
> Okena or Entercept or anything like that, or simply for just taking
> root. An exploit for this was released as part of the Shellcoder's
> Handbook.
> 
> There is a Solaris patch that appears to make this exploit ineffective.
> http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%
> 2F57479&zone_32=category%3Asecurity

I note that the current patch (as of about 2004-03-25 11:30-08:00) is 
108528-29 (not 108528-27 as suggested by the sunsolve URL above).

http://sunsolve.sun.com/pub-cgi/findPatch.pl?patchid=108528&rev=29

--
Jonathan Leffler ([email protected])
STSM, Informix Database Engineering, IBM Data Management
4100 Bohannon Drive, Menlo Park, CA 94025
Tel: +1 650-926-6921   Tie-Line: 630-6921
      "I don't suffer from insanity; I enjoy every minute of it!"