P-107: Security Vulnerability in Solaris 8 DHCP Administration Utilities
Privacy and Legal Notice
INFORMATION BULLETIN
P-107: Security Vulnerability in Solaris 8 DHCP Administration Utilities
[Sun Alert ID: 57727]
January 25, 2005 18:00 GMT
|
| PROBLEM: |
There is a security vulnerability in Solaris 8 in the DHCP administration utilities
dhcpconfig(1M), pntadm(1M), and dhcpmgr(1M).
|
| PLATFORM: |
Sparc
* Solaris 8 with patch 109077-02 through 109077-08 and without patch 109077-09
x86
* Solaris 8 with patch 109078-02 through 109078-08 and without patch 109078-09
Note: Solaris 7 & 9 are not affected by this issue.
|
| DAMAGE: |
May allow an unprivileged local user the ability to execute arbitrary code with the
privileges of root.
|
| SOLUTION: |
Upgrade to the appropriate versions.
|
|
VULNERABILITY
ASSESSMENT: |
The risk is MEDIUM. May allow an unprivileged local user the ability to execute
arbitrary code with the privileges of root.
|
|
[***** Start Sun Alert ID: 57727 *****]
Sun(sm) Alert Notification
Sun Alert ID: 57727
Synopsis: Security Vulnerability in Solaris 8 DHCP Administration Utilities
Category: Security
Product: Solaris
BugIDs: 4646306
Avoidance: Patch
State: Resolved
Date Released: 19-Jan-2005
Date Closed: 19-Jan-2005
Date Modified:
1. Impact A security vulnerability in the DHCP administration utilities dhcpconfig(1M), pntadm(1M),
and dhcpmgr(1M) may allow an unprivileged local user the ability to execute arbitrary code with the privileges
of root.
2. Contributing Factors This issue can occur in the following releases:
SPARC Platform
- Solaris 8 with patch 109077-02 through 109077-08 and without patch 109077-09
x86 Platform
- Solaris 8 with patch 109078-02 through 109078-08 and without patch 109078-09
Note: Solaris 7 and Solaris 9 are not affected by this issue.
A system is only vulnerable to this issue if the DHCP server packages have been installed.
To determine if the DHCP server packages have been installed, the following command can be run:
$ pkginfo SUNWdhcm SUNWdhcsu
3. Symptoms There are no predictable symptoms that would indicate the described issue has occurred.
Solution Summary Top
4. Relief/Workaround To work around the described issue, edit each of the following files:
/usr/lib/inet/dhcp/svcadm/pntadm
/usr/lib/inet/dhcp/svcadm/dhcpconfig
/usr/sadm/admin/bin/dhcpmgr
and modify the following line:
From:
LD_LIBRARY_PATH=${LD_LIBRARY_PATH}:${WBEMDIR}
To:
LD_LIBRARY_PATH=${WBEMDIR}
5. Resolution This issue is addressed in the following releases:
SPARC Platform
- Solaris 8 with patch 109077-09 or later
x86 Platform
- Solaris 8 with patch 109078-09 or later
This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may
contain information provided by third parties. The issues described in this Sun Alert notification may or
may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information
contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING
THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED
HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being
provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do
not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the
purposes contemplated by these agreements.
Copyright 2000-2005 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights
reserved.
[***** End Sun Alert ID: 57727 *****]
CIAC wishes to acknowledge the contributions of Sun Microsystems for the
information contained in this bulletin.
CIAC services are available to DOE, DOE Contractors, and the NIH. CIAC
can be contacted at:
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org
This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.
UCRL-MI-119788
[Privacy and Legal Notice]