SunOS LD_LIBRARY_PATH and LD_OPTIONS...

- AV AC AU C I A
发布: 1992-05-27
修订: 2025-04-13

There exists a vulnerability involving environment variables and setuid/setgid programs under SunOS 4.0 and higher. A dynamically-linked program that is invoked by a setuid/setgid program has access to the caller's LD_* environmental variables if the setuid/setgid program sets the real and effective UIDs to be equal and the real and effective GIDs to be equal before the dynamically-linked program is executed. A vulnerability exists if the UIDs and GIDs are not equal to those of the user that invoked the setuid/setgid program. This is Sun Bug ID 1085851 and 1085853. In particular, SunOS /usr/lib/sendmail, /usr/bin/login, /usr/bin/su, and /usr/5bin/su are vulnerable to this problem. In-house and third-party software can also be impacted by this vulnerability. For example, the current versions of rnews, sudo, smount, and npasswd are known to be vulnerable under SunOS. This or similar vulnerabilities have been found in other unix operating systems. It seems Sun's solution is to call...

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息